New Kaspersky GReAT research has shown that Project CAV3RN, a cyberespionage toolkit used to target Israeli organizations, continues to evolve, introducing sophisticated components and tools used for communication with attackers. By abusing legitimate services – previously Outlook calendar events and in this occasion, Google Apps Script – the framework blends its network traffic with normal network activity, complicating detection for security solutions. As a result, sensitive information can be acquired by the attackers.
Continued tracking of CAV3RN in early August 2026 uncovered several previously undocumented components that expanded the framework’s communication and orchestration capabilities. The main finding is a complex command-and-control module that selects between direct HTTPS traffic and a Google Apps Script relay for each transaction. Google Apps Script is a cloud-based, low-code development platform used to automate tasks, customize features, and integrate workflows.
Furthermore, the attackers have equipped the malware’s new communication module with a backup mechanism in case its Google Apps Script channel is blocked or replaced. The attackers can publish updated connection details through a separate channel controlled by them, and the malware checks for these updates automatically and can reconnect through a new Google Apps Script deployment without replacing the malware component on the infected device. This helps the attackers maintain access when the original communication channel becomes unavailable.
“Given its development pace, modular design, and operational tempo, we assess that CAV3RN will likely continue to expand and refine its arsenal. The threat actors behind this campaign are highly adaptable, seamlessly shifting from Microsoft Graph to Google Apps Script to camouflage their command-and-control traffic within legitimate, everyday network activity. This tactic of ‘living off the cloud’ highlights a deeply targeted, well-resourced, and sophisticated operation. Standard security perimeters are often blind to this type of evasion. We will continue tracking the framework closely and reporting on its activity in the wild to ensure organizations can stay one step ahead of these elusive threats,” comments Sergey Lozhkin, Head of Research Center for APAC and META at Kaspersky GReAT.
Previously, in April 2026, Kaspersky observed a major redesign of the Project CAV3RN cyberespionage framework, which evolved from a simple downloader–executor–uploader architecture into a controller-based, modular platform with a dedicated component for the malware to communicate with the attackers and an extensible plugin system. The new architecture made it easier for the operators to add new capabilities and adapt the malware over time. This redesign contributed to a significant increase in the framework's flexibility and sophistication for long-term espionage operations.
In July 2026, Kaspersky published a technical analysis that showed that the module uses Microsoft Outlook Calendar events via Microsoft Graph as its primary command-and-control channel and falls back to DNS records to recover updated configuration if Graph authentication or tenant validation fails.
More information is available in the report on Securelist.
To be better protected against sophisticated attacks, Kaspersky recommends:
- Deploying proven threat-hunting and Endpoint Detection and Response solutions
- Fortifying and isolating legacy systems
- Implementing advanced behavioral and network monitoring
About the Global Research & Analysis Team
Established in 2008, Global Research & Analysis Team (GReAT) operates at the very heart of Kaspersky, uncovering APTs, cyber-espionage campaigns, major malware, ransomware and underground cyber-criminal trends across the world. Today GReAT consists of 35+ experts working globally – in Europe, Russia, Latin America, Asia and the Middle East. Talented security professionals provide company leadership in anti-malware research and innovation, bringing unrivaled expertise, passion and curiosity to the discovery and analysis of cyberthreats.