Skip to main content

Cyber-Spying Framework Targeting Israel Now Hides in Google Cloud Traffic

Courtroom-sketch editorial illustration of a hooded figure's eyes peering toward the camera through rust-red fabric, with slate-blue shadows across the face.

Kaspersky researchers said Project CAV3RN, an active modular cyberespionage framework aimed at Israeli organizations, has added previously undocumented components discovered in early August. A new GoogleService.dll module uses DNS responses to switch between direct HTTPS traffic and Google Apps Script relays, allowing operators to rotate the relay without reinstalling the framework. Kaspersky said the system also includes a local broker that discovers, loads and upgrades components, helping malicious traffic blend into legitimate cloud activity. Kaspersky Israel CTO Assaf Hazan described the operation as focused, sophisticated and well resourced, and said its operators had moved from Microsoft services to Google services to preserve covert access.

Sources

Primary sources:1Secondary sources:2

Related stories

  1. UK Power Plant Shut for Four Days in Reported Iran-Linked Cyberattack
  2. Mossad Sources Call Removals Over Shelved Iran Plan a Political Blame Shift
  3. Case-File Videos Detail Jacob Perl’s Surveillance for Iranian Handler
  4. Iranian Daily Details How Khamenei Audio Could Expose His Location
  5. Iranian Diplomat Says IRGC May Strike First if U.S. Talks Fail

Something went wrong

We couldn't complete that action. Check your connection and try again.