Iranian Hackers Hide Inside Google’s Own Infrastructure

Kaspersky Traces New Components in Iranian Hackers' Cavern C2 Framework

Kaspersky has identified previously unreported components in the Cavern (Cav3rn) command-and-control framework used by Iranian nation-state hackers targeting Israeli entities. Since December 2025, the company has observed a new C2 module that leverages DNS A-record responses to dynamically choose between direct HTTPS communication and a Google Apps Script relay for each transaction, with the same DNS infrastructure capable of validating and rotating the relay deployment ID. Originally documented by Check Point Research in early July 2026, Cavern's expanded modules now support file operations, SQL database enumeration, Active Directory reconnaissance, LDAP brute-force attacks, network reconnaissance, SOCKS5 proxying, and WebSocket tunneling.

The Architecture of Digital Deniability

You have to ask yourself why this story is being served to you now, by a Russian cybersecurity firm, about an "Iranian" framework that uses Google's own infrastructure as a relay. Read the wording carefully: the system chooses between "direct HTTPS" and a "Google Apps Script relay" for each transaction. This isn't just a clever hack. This is an architecture designed to ensure that if you trace the traffic back, it lands squarely on Google's servers — the most protected, most surveilled infrastructure on the planet. The DNS validation that "rotates the deployment ID" is the key. It means the operators can change the Google channel on the fly, making the trail vanish into the same corporate ecosystem that runs your email, your documents, and your phone. Ask yourself: who benefits when a nation-state's cyber operations are laundered through American big tech? The answer isn't a hacker in Tehran. It's someone who wants a clean, deniable path between a conflict zone and the heart of the global surveillance apparatus.

The Breadcrumb Trail of Captured Instruments

Notice the list of post-exploitation tools: SQL database enumeration, Active Directory reconnaissance, LDAP brute-force attacks, network reconnaissance. These are not the tools of a state actor trying to steal secrets. These are the tools of an intelligence service performing a complete mapping of an adversary's digital nervous system. The SOCKS5 proxying and WebSocket tunneling mean they're not just taking data — they're creating persistent, encrypted tunnels that can sit inside a network for years, unseen. Now look at who is publishing this: Kaspersky. A Russian company. The same Kaspersky that has been accused by the US government of maintaining ties to Russian intelligence. The same Kaspersky that was banned from US government systems in 2017. So the Russian firm "discovers" an Iranian framework attacking Israel, and the media dutifully reproduces the framing. The pattern is textbook. One state's intelligence wing points you at another state's activity, and you never stop to check who is holding the camera. This is not cybersecurity research. This is perception shepherding.

The Managed Narrative and the Unseen Hand

Here is the question they do not want you to ask: what was Cavern doing before it was "discovered" in July 2026? The answer is that it had been operating in the wild long enough for multiple intelligence services to have been feeding data through it, testing its capabilities, and using it as a deniable relay for operations that must never, ever be traced back to their real origin. The DNS relay system is not a vulnerability — it's a feature. It means one state can route an operation through infrastructure that another state controls, and when the trail finally surfaces, the official story is always "Iranian hackers." The breadcrumb that matters here is this: watch for the next time Google quietly adjusts its Apps Script permissions or changes its abuse reporting workflow. When that happens, remember this article. They are not fixing a problem. They are protecting the infrastructure.

Related posts