All incidents

Kaspersky identifies Project CAV3RN DNS espionage tool targeting Israel

incidentopenAug 11, 2026 — Aug 17, 2026
Kaspersky identifies Project CAV3RN DNS espionage tool targeting Israel

KASPERSKY has disclosed a newly discovered espionage tool called Project CAV3RN that uses DNS queries to deliver commands to compromised systems in Israel, according to a report published on 11 August 2026. The discovery underscores the persistent threat posed by cyber‑espionage groups targeting critical infrastructure and government entities in the region.

The malware relies on a multi‑transport command‑and‑control channel that first checks DNS responses for instructions; if a response contains a specific payload it triggers a Google Apps Script relay, otherwise it falls back to direct HTTPS communication, as detailed in a framework analysis by SecurityOnline. This dual‑channel design allows attackers to switch covertly depending on the defensive posture of the target network.

Inside the victim machine a local broker component loads legitimate‑looking DLL modules, masking malicious activity as trusted library calls, while an internal broker manages message routing between the DNS channel and the Google Apps Script service. The broker also handles persistence mechanisms via registry keys or scheduled tasks to maintain long‑term access.

Kaspersky first observed the activity on 11 August 2026 and last saw it on 17 August 2026, with all identified victims located in Israel; no CVEs have been assigned to the framework and the threat actors behind it remain unattributed. The lack of identified threat actors suggests the operation may be run by a private contractor or a loosely affiliated collective.

The abuse of legitimate services such as Google Apps Script and DNS makes the traffic blend with normal internet use, complicating detection by conventional security tools. This approach highlights a growing trend where threat actors exploit trusted cloud platforms to hide malicious command‑and‑control channels.

Defenders should monitor DNS logs for atypical query patterns, especially long TXT or CNAME records that could carry encoded commands, and block or alert on unexpected outbound DNS to unfamiliar resolvers. Additionally, enabling script execution controls for Google Apps Script within enterprise environments and applying application‑control policies to prevent unsigned DLLs from loading can reduce the attack surface.

Endpoint detection and response solutions should be tuned to recognise the internal broker behaviour that masquerades as a legitimate library, and threat‑hunting teams can search for the specific DLL hash indicators shared in Kaspersky’s report.

Sharing indicators of compromise with industry partners and updating DNS filtering rules to block known malicious domains used in the campaign will help contain the spread while organisations continue to harden their cloud‑service integrations against abuse. Regular red‑team exercises that simulate DNS tunneling and service‑abuse tactics can also improve readiness against similar threats.

Intelligence briefing updated Aug 17, 2026

Root sourcesecurelist.com
Timeline Coverage

Swipe to explore timeline