Cyber-Spying Framework Targeting Israel Now Hides in Google Cloud Traffic

Kaspersky researchers said Project CAV3RN, an active modular cyberespionage framework aimed at Israeli organizations, has added previously undocumented components discovered in early August. A new GoogleService.dll module uses DNS responses to switch between direct HTTPS traffic and Google Apps Script relays, allowing operators to rotate the relay without reinstalling the framework. Kaspersky said the system also includes a local broker that discovers, loads and upgrades components, helping malicious traffic blend into legitimate cloud activity. Kaspersky Israel CTO Assaf Hazan described the operation as focused, sophisticated and well resourced, and said its operators had moved from Microsoft services to Google services to preserve covert access.