PROJECT CAV3RN is a sophisticated modular espionage framework targeting Israeli entities, characterized by its evolving architecture and command-and-control (C2) capabilities. Key components include a multi-transport C2 module that utilizes DNS responses to alternate between a Google Apps Script relay and direct HTTPS communication. Additionally, the framework incorporates a local broker for managing DLL components and enhancing message routing.
The report highlights the framework's abuse of legitimate services for stealthy operations, complicating network detection efforts. Future tracking of CAV3RN's activity is essential due to its rapid development and operation.