Threat Intelligence

Iranian Hackers Refine 'Cavern' Malware to Hide Inside Everyday Web Traffic

The Hacker News · 18 Aug 2026
Key Takeaway Businesses should ensure their network monitoring tools can inspect DNS traffic and cloud service activity, not just obvious malware signatures, since attackers increasingly hide inside trusted platforms.

Security researchers at Kaspersky have been tracking the continued development of a hacking tool known as Cavern (also called Cav3rn), linked to Iranian nation-state actors targeting organisations in Israel. Since December 2025, ongoing monitoring has uncovered previously unreported components that expand the malware's capabilities.

What makes Cavern notable is its use of everyday internet services, such as DNS lookups and Google Apps Script, to communicate with infected systems. By blending malicious traffic into normal-looking web activity, attackers make it much harder for security tools to spot the difference between legitimate business communications and command-and-control instructions from hackers.

While this campaign is currently focused on Israeli targets, the techniques involved, using trusted cloud platforms and common internet protocols to mask malicious activity, are increasingly common across the threat landscape. Australian businesses using Google Workspace or similar cloud tools should be aware that attackers are finding creative ways to hide within normal network traffic, making detection more challenging for traditional security monitoring.

nation-state hacking command-and-control DNS security cloud security Iran

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.