<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/project-cav3rn-uses-google-apps-script-for-stealthy-c2-in-israel-iblbspak5" -->

---
title: Project CAV3RN uses Google Apps Script for stealthy C2...
description: Kaspersky&#x27;s GReAT team documents newly discovered components of Project CAV3RN, a modular espionage framework targeting Israel. The key finding is...
canonical: https://daily.dev/posts/project-cav3rn-uses-google-apps-script-for-stealthy-c2-in-israel-iblbspak5
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Project CAV3RN uses Google Apps Script for stealthy C2 in Israel | daily.dev
og:description: Kaspersky&#x27;s GReAT team documents newly discovered components of Project CAV3RN, a modular espionage framework targeting Israel. The key finding is...
og:url: https://daily.dev/posts/project-cav3rn-uses-google-apps-script-for-stealthy-c2-in-israel-iblbspak5
og:image: https://api.daily.dev/og/posts/iBlBSPAk5.png
og:image:alt: Project CAV3RN uses Google Apps Script for stealthy C2 in Israel
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Project CAV3RN uses Google Apps Script for stealthy C2 in Israel

**[Securelist](https://daily.dev/sources/securelist)** · 8 min read · 1 upvotes · 0 comments

## Summary

Kaspersky's GReAT team documents newly discovered components of Project CAV3RN, a modular espionage framework targeting Israel. The key finding is GoogleService.dll, a .NET 8 NativeAOT C2 module that uses DNS A-record responses to dynamically route traffic between direct HTTPS and a Google Apps Script relay, blending malicious traffic with legitimate Google services. The DNS infrastructure also enables the operator to rotate the Google Apps Script deployment ID via encoded DNS responses. A second component, rnp.dll, serves as the inter-component broker, masquerading as the RNP OpenPGP library while loading, routing messages between, and hot-swapping DLL modules. The C2 infrastructure centers on studiotikva[.]com, a domain that may have been acquired from a legitimate Israeli business after expiration. IoCs including file hashes and domains are provided.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://securelist.com/project-cav3rn-continues/120991>

## Questions this post answers

### How does the CAV3RN malware decide whether to use Google Apps Script or direct HTTPS for command and control?

The malware performs a DNS A-record query before each transaction, and the fourth octet of the response, combined with the current error state, determines the channel. For example, a response of 120 in the None state selects Google Apps Script, while 130 in most states selects Direct HTTPS; 140 triggers an exception and other values default to Google Apps Script.

_Tracking C2 evasion techniques like DNS-based channel switching helps defenders stay ahead of espionage tooling, a use case daily.dev supports for security researchers._

### How does the CAV3RN malware hide its command and control traffic inside Google Apps Script?

The module inserts a recovered deployment ID into a script.google.com URL and sends an outer POST request whose JSON payload instructs the Apps Script relay to issue a GET request to an actor-controlled upstream backend at api.studiotikva.com. Direct browser access to the same URL only shows a decoy page reading 'This application is running normally,' masking the relay's true purpose.

_Understanding how attackers abuse legitimate cloud services for C2 helps teams tune detection rules, a need daily.dev serves for security practitioners._

### What is the studiotikva.com domain used for in the CAV3RN cyberespionage campaign?

It is the primary infrastructure domain for CAV3RN's command and control, registered through Dynadot and hosted by RouterHosting LLC on IPs 144.172.115.17 and 144.172.104.82. Originally a legitimate Wix-hosted Israeli business site before expiring in February 2026, it was re-registered in May 2026 and now serves both authoritative DNS for C2 channel selection and a cover website themed around a fictitious 'Studio Tikva' business.

_Following infrastructure indicators like these helps analysts attribute and block emerging campaigns, work daily.dev keeps threat researchers current on._

## Similar posts on daily.dev

- [Cavern Manticore: Exposing Iran-Linked Modular C2 Framework](https://daily.dev/posts/cavern-manticore-exposing-iran-linked-modular-c2-framework-d9buxcnjl) · Check Point Research · 0 upvotes · 0 comments

---

Tags: [#.net](https://daily.dev/tags/.net), [#malware](https://daily.dev/tags/malware), [#dns](https://daily.dev/tags/dns)

[View this post on daily.dev](https://daily.dev/posts/project-cav3rn-uses-google-apps-script-for-stealthy-c2-in-israel-iblbspak5)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Project CAV3RN uses Google Apps Script for stealthy C2 in Israel","url":"https://daily.dev/posts/project-cav3rn-uses-google-apps-script-for-stealthy-c2-in-israel-iblbspak5","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/project-cav3rn-uses-google-apps-script-for-stealthy-c2-in-israel-iblbspak5"},"datePublished":"2026-08-11T10:01:34.137Z","dateModified":"2026-09-14T06:04:43.030Z","description":"Kaspersky's GReAT team documents newly discovered components of Project CAV3RN, a modular espionage framework targeting Israel. The key finding is...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/87f87257e6e7bd4236ad182bdebd3aea?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/87f87257e6e7bd4236ad182bdebd3aea?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Securelist","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Securelist","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/e4b9f556af7a4e74a179787362dd5b07","url":"https://daily.dev/sources/securelist"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/project-cav3rn-uses-google-apps-script-for-stealthy-c2-in-israel-iblbspak5","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":".net,malware,dns","timeRequired":"PT8M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Securelist","item":"https://daily.dev/sources/securelist"},{"@type":"ListItem","position":3,"name":"Project CAV3RN uses Google Apps Script for stealthy C2 in Israel"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/project-cav3rn-uses-google-apps-script-for-stealthy-c2-in-israel-iblbspak5#faq","mainEntity":[{"@type":"Question","name":"How does the CAV3RN malware decide whether to use Google Apps Script or direct HTTPS for command and control?","acceptedAnswer":{"@type":"Answer","text":"The malware performs a DNS A-record query before each transaction, and the fourth octet of the response, combined with the current error state, determines the channel. For example, a response of 120 in the None state selects Google Apps Script, while 130 in most states selects Direct HTTPS; 140 triggers an exception and other values default to Google Apps Script. Tracking C2 evasion techniques like DNS-based channel switching helps defenders stay ahead of espionage tooling, a use case daily.dev supports for security researchers."}},{"@type":"Question","name":"How does the CAV3RN malware hide its command and control traffic inside Google Apps Script?","acceptedAnswer":{"@type":"Answer","text":"The module inserts a recovered deployment ID into a script.google.com URL and sends an outer POST request whose JSON payload instructs the Apps Script relay to issue a GET request to an actor-controlled upstream backend at api.studiotikva.com. Direct browser access to the same URL only shows a decoy page reading 'This application is running normally,' masking the relay's true purpose. Understanding how attackers abuse legitimate cloud services for C2 helps teams tune detection rules, a need daily.dev serves for security practitioners."}},{"@type":"Question","name":"What is the studiotikva.com domain used for in the CAV3RN cyberespionage campaign?","acceptedAnswer":{"@type":"Answer","text":"It is the primary infrastructure domain for CAV3RN's command and control, registered through Dynadot and hosted by RouterHosting LLC on IPs 144.172.115.17 and 144.172.104.82. Originally a legitimate Wix-hosted Israeli business site before expiring in February 2026, it was re-registered in May 2026 and now serves both authoritative DNS for C2 channel selection and a cover website themed around a fictitious 'Studio Tikva' business. Following infrastructure indicators like these helps analysts attribute and block emerging campaigns, work daily.dev keeps threat researchers current on."}}]}
```

