Iranian Hackers Refine 'Cavern' Toolkit to Hide Inside Google and DNS Traffic

Kaspersky says the Cav3rn framework, aimed at Israeli targets, now hides its commands inside services most networks trust by default.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge photoreal editorial image of a darkened data center corridor with a single amber warning light reflecting off polished server racks, an
Share

Key points

  • Kaspersky has been tracking a hacking toolkit called Cavern (also written Cav3rn) since December 2025, and links it to Iranian government hackers targeting organisations in Israel.
  • The attackers hide their instructions inside ordinary-looking Domain Name System (DNS) lookups and Google Apps Script traffic, making the activity blend in with everyday internet noise.
  • Researchers found new, previously unreported pieces of the toolkit that widen what the attackers can do on a hacked machine.
  • Israeli organisations are the main targets, but the technique of hiding inside trusted cloud services is a warning for defenders everywhere.

Iranian government hackers have quietly upgraded a custom hacking toolkit called Cavern, and the new version is built to slip past company firewalls by pretending to be normal Google and internet lookup traffic.

That is the finding from Kaspersky, the Russian cybersecurity firm that has been watching the group since December 2025. Its researchers say they have found fresh components of the Cavern framework (also spelled Cav3rn) that had not been described publicly before.

The targets, so far, sit inside Israel.

What is Cavern, in plain English?

Cavern is a command-and-control framework: the remote-control software a hacking group installs on a victim's computer so it can send orders and pull data back out. Think of it as the attackers' hidden dashboard for a machine they have broken into.

Most defensive tools spot this kind of traffic because it looks unusual. The Cavern operators have gone to real trouble to make theirs look boring.

How does it hide?

It disguises its instructions as two kinds of traffic almost every office network already allows: Domain Name System lookups, and requests to Google's own servers.

DNS is the internet's phone book. Every time your laptop opens a website, it asks a DNS server, "what is the address for this name?" That chatter happens constantly, and firewalls rarely block it. Cavern smuggles its commands inside those lookups, so the traffic reads like a computer quietly resolving domain names.

The framework also talks to Google Apps Script, a legitimate Google service that lets developers run small programs tied to Google accounts. Because the connection goes to a real Google address over encrypted HTTPS, it looks, from the outside, like a normal employee using a Google product.

The result: the attacker's remote-control channel is buried inside two services a company cannot easily switch off.

Who is behind it?

Kaspersky attributes the activity to an Iranian nation-state cluster, meaning a hacking team working on behalf of the Iranian government rather than for money. The Hacker News, which first flagged the update, notes the group's focus has stayed on Israeli entities.

Kaspersky has not, in the material available, named the specific victims or the exact sectors hit.

What is actually new in this version?

Kaspersky says its continued monitoring since late 2025 turned up components of Cavern that had not been reported before. These extra pieces expand what operators can do once they are inside a network, though the firm has kept some of the technical detail out of public view while investigations continue.

Detail What we know
Toolkit name Cavern (also Cav3rn)
Attributed to Iranian government hackers
Main targets Organisations in Israel
Tracked since December 2025
Hiding channels DNS lookups, Google Apps Script
Reported by Kaspersky

Should ordinary people worry?

Not directly. This is targeted espionage aimed at specific organisations, not a mass campaign against consumers. There is no patch to install on your phone.

The useful takeaway is for the people who run company networks: traffic to Google services and steady DNS chatter are not automatically safe. Attackers now count on defenders trusting them.

What defenders should watch

Security teams protecting Israeli organisations, or any group Iran has historically targeted, should look for oddly patterned DNS queries and unexplained connections to Google Apps Script endpoints from machines that have no business using them. Both are cheap to log and revealing when you do.

© 2026 Threat Vectr