Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Kaspersky details Iranian Cavern Manticore's expanded C2 framework using DNS and Google Apps Script, plus APT42's TAMECAT spyware in nuclear-sector phishing.
Kaspersky reported new components in the Cavern (Cav3rn) C2 framework, used by Iranian MOIS-affiliated Cavern Manticore (with overlaps to MuddyWater and OilRig's Lyceum) against Israeli entities, monitored since December 2025. The new GoogleService.dll module performs DNS A-record queries to choose between direct HTTPS and a Google Apps Script relay per transaction, with the DNS infrastructure able to rotate the Google deployment ID; Kaspersky also found an inter-component broker (rnp.dll) and linked the framework's plugin-based pivot to late April 2026. Separately, Group-IB and Kaspersky detailed HOLLOWGRAPH, a .NET NativeAOT DLL first seen in the wild June 7, 2026, that uses Microsoft 365 calendar events via the Graph API as two-way dead drops dated May 13, 2050, with DNS tunneling refreshing Entra ID credentials. DarkAtlas also reported APT42's TAMECAT modular surveillance framework delivered via LNK masquerading as PDFs in spear-phishing targeting the nuclear energy sector in April-May 2026, with the group using generative AI to accelerate operations.
Microsoft security advisory – August 2026 monthly rollup (AV26-804) – Update 2
Canada's Cyber Centre updated advisory AV26-804 relaying Microsoft's August 2026 monthly rollup of vulnerabilities across .NET and Azure products.
The Canadian Centre for Cyber Security advisory AV26-804, updated August 27, 2026, relays Microsoft's August 2026 monthly security rollup originally issued August 11. Affected products include .NET 8.0, 9.0, and 10.0 on Linux, macOS, and Windows, plus many Azure services. Listed Azure components include Azure Kubernetes Service, Azure SQL Database, Azure Service Bus, Azure Active Directory, Azure Logic Apps, and Azure Monitor Agent.