Cavern C2는 합법적인 트래픽으로 위장하기 위해 DNS와 Google Apps Script를 사용하여 발전해왔다.
사이버 보안 연구원들은 이란 국가 해커들이 이스라엘을 겨냥한 공격에서 사용하는 Cavern(command-and-control) 프레임워크의 지속적인 발전을 추적해왔다. Kaspersky에 따르면, 이 위협 활동 클러스터에 대한 지속적인 모니터링을 통해 이전에 보고되지 않았던 구성 요소들이 발견되었다. 이 새로운 요소들은 Cavern C2의 능력을 확장시키며 공격의 은폐를 더욱 용이하게 만든다.
Cavern C2 evolves by using DNS and Google Apps Script to blend into legitimate traffic.
Cybersecurity researchers have tracked the ongoing evolution of the Cavern command-and-control framework used by Iranian state hackers targeting entities in Israel. Kaspersky noted that its continuous monitoring of this threat activity cluster has resulted in the discovery of previously unreported components. These new elements enhance Cavern C2's capabilities, making it easier to disguise attacks.