Security08:08 · 1h ago

Iranian Cyber Espionage Group Shifts to Google Cloud Services to Target Israeli Organizations

WallaCenter
Translated & summarized from Walla by baba
The story · English

The Iranian cyber espionage campaign known as Project CAV3RN, which targets Israeli organizations, has evolved by shifting its infrastructure from Microsoft cloud services to Google cloud platforms. A new study by Kaspersky's GReAT team revealed previously undocumented components in the attack framework, including a communication and control module that dynamically chooses between direct HTTPS connections and Google Apps Script to transmit data. This tactic allows attackers to disguise malicious traffic as legitimate network activity, complicating detection and blocking efforts.

Google Apps Script, a legitimate Google service used for automation and development, is exploited here to mask the attackers' communications within normal cloud traffic. This approach, known as "Living off the Cloud," leverages trusted cloud infrastructures to evade security measures. Blocking major cloud services is often impractical for organizations, making it difficult to distinguish between routine business operations and malicious activity.

Additionally, CAV3RN now includes a recovery mechanism enabling attackers to maintain persistent access even if one communication channel is blocked. The malware can independently seek updates through alternate channels and resume contact without needing reinstallation. This modular platform, identified since April 2026, allows continuous addition of components to enhance espionage capabilities and maintain a stealthy presence.

Kaspersky previously reported in July 2026 that the campaign used Microsoft Outlook and Microsoft Graph for communication management. The recent adoption of Google Apps Script demonstrates the attackers' adaptability in switching between major cloud providers to suit operational needs. Asaf Hazan, CTO of Kaspersky Israel, emphasized the attackers' high adaptability and the challenge posed by their ability to blend malicious traffic with legitimate cloud services, making detection and mitigation more complex.

For Israeli organizations, the evolving threat requires not only identifying malware or blocking suspicious servers but also addressing attacks that intentionally mimic normal cloud traffic, increasing the difficulty for security teams to protect their networks effectively.

Read the original at Walla
Open the live terminal