A sophisticated cyber threat actor has been using a custom-built command-and-control (C2) framework, dubbed Cavern C2, to evade detection and blend into legitimate network traffic. The framework’s unique approach involves leveraging DNS queries and Google Apps Script to maintain a low profile, making it particularly challenging for security teams to detect.
The Cavern C2 framework has been identified as being used in a number of high-profile attacks, targeting organizations across various industries, including finance, healthcare, and government. While the exact scope of the campaign is still unclear, researchers warn that the potential impact could be significant, given the framework’s ability to persist on compromised networks for extended periods.
At its core, Cavern C2 relies on DNS queries to communicate with command-and-control servers, allowing attackers to maintain a stealthy presence within compromised networks. To further disguise its activity, the framework employs Google Apps Script, which is used to establish encrypted communication channels between infected hosts and the C2 infrastructure. This approach enables attackers to mimic legitimate network traffic patterns, making it increasingly difficult for security solutions to detect.
The framework’s designers have also implemented a range of evasive techniques, including domain name system (DNS) tunneling and the use of custom-built protocols to communicate with compromised systems. These tactics enable Cavern C2 to adapt and evolve in response to changing network conditions, further complicating detection efforts.
One of the key concerns surrounding Cavern C2 is its ability to facilitate lateral movement within compromised networks. By exploiting cross-domain privilege escalation vulnerabilities, attackers can establish a foothold on multiple systems, creating a web of interconnected attack paths that allow them to move freely between targets. This capability effectively enables attackers to “map” and “sever breach routes at key choke points,” as described in the accompanying research.
As researchers continue to analyze Cavern C2 and its tactics, it becomes clear that this threat actor is pushing the boundaries of what is possible in terms of stealthy network activity. Given the framework’s demonstrated ability to evade detection and blend into legitimate traffic patterns, organizations must remain vigilant and proactive in their security measures. To mitigate potential risks, we recommend that readers prioritize regular software updates, implement robust DNS filtering and monitoring capabilities, and stay informed about emerging threats through reputable sources like CyberNews.work.
Source: The Hacker News — 2026-08-17