[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fVjIEc_0TEZB_PG6xdnzUFJGJhi_IIolr0Tjfuy1UG00":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"976f7cd9-35c3-43f9-98e1-99bf10c53c28","iranian-hackers-abuse-dns-and-cloud-apis-to-hide-c2-traffic","70448a7b-cfc1-420c-8bf3-c18fbd7e6bdc","Iranian Hackers Abuse DNS and Cloud APIs to Hide C2 Traffic","The Cavern C2 framework demonstrates how sophisticated nation-state actors exploit trusted cloud services — Google Apps Script, Microsoft 365 Graph API, and standard DNS — to camouflage malicious command-and-control traffic within legitimate-looking network activity. Because these platforms are widely trusted and often allowed through enterprise firewalls, traditional perimeter defenses fail to detect the covert channel. The HOLLOWGRAPH module's abuse of Microsoft 365 calendars for data exfiltration is particularly dangerous because it exploits authenticated, encrypted SaaS traffic that many organizations do not deeply inspect. This matters because defenders who rely solely on blocklists or signature-based detection will miss these channels entirely, giving attackers persistent, stealthy access.","**Immediate actions:**\n- Audit and restrict which internal systems are permitted to make outbound DNS queries and HTTPS calls to cloud platforms like Google and Microsoft.\n- Enable Microsoft 365 audit logging and alert on anomalous Graph API access patterns, especially calendar read\u002Fwrite operations by non-interactive service accounts.\n- Deploy DNS security controls (e.g., DNS-over-HTTPS inspection, RPZ policies) to detect and block unusual DNS A-record query patterns used for C2 signaling.\n\n**Detection measures:**\n- Implement behavioral analytics (UEBA\u002FNDR) to baseline and flag abnormal outbound traffic volumes to legitimate cloud services such as script.google.com or graph.microsoft.com.\n- Establish SIEM rules to correlate DNS query spikes with subsequent HTTPS connections to cloud relay infrastructure as an indicator of C2 switching behavior.\n- Monitor OAuth token issuance and Graph API permission grants for service principals that were not provisioned through standard change management processes.\n\n**Long-term improvements:**\n- Apply Zero Trust network segmentation so that workstations and servers have least-privilege outbound access, preventing unauthorized use of cloud APIs as exfiltration channels.\n- Implement Cloud Access Security Broker (CASB) solutions to provide deep inspection and policy enforcement over SaaS API traffic, including Microsoft 365 and Google Workspace.\n- Conduct regular threat hunting exercises specifically targeting living-off-the-land and cloud-abuse TTPs mapped to MuddyWater and Lyceum actor profiles.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 13 – Network Monitoring and Defense","CIS Control 6 – Access Control Management","CIS Control 8 – Audit Log Management","NIST SP 800-53 SI-4 – System Monitoring","NIST SP 800-53 AC-17 – Remote Access","NIST SP 800-53 SC-7 – Boundary Protection","MITRE ATT&CK T1071.004 – Application Layer Protocol: DNS","MITRE ATT&CK T1102 – Web Service (C2 via cloud services)","MITRE ATT&CK T1048 – Exfiltration Over Alternative Protocol","NIST CSF DE.CM-1 – Network Communications Monitored","GDPR Article 32 – Security of Processing (data exfiltration risk)","published","2026-08-17T20:21:38.647159+00:00","2026-08-17T20:21:38.331+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fcavern-c2-uses-dns-and-google-apps.html","cavern-c2-uses-dns-and-google-apps-script-to-blend-into-legitimate-traffic-788b4d","Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":38,"name":39,"slug":40,"description":41,"color":42},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":44,"name":45,"slug":46,"description":47,"color":48},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[50],{"id":51,"date":52,"edition":53,"title":54,"audio_url":55},"957fca4a-7e5f-41d0-af3e-4fae66d946e0","2026-08-18","morning","ThreatNoir Morning Brief — August 18","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-18\u002Fthreatnoir-morning-brief-2026-08-18.mp3"]