B
今週中
イランの国家支援型ハッカー集団が使用するC2フレームワーク「Cavern」の進化
📌 一言でいうと
イランの国家支援型ハッカー集団が使用するC2フレームワーク「Cavern」の進化が確認されました。このツールはDNS Aレコードの応答を利用して、直接的なHTTPS通信とGoogle Apps Scriptリレーを動的に切り替えることで、正当なトラフィックに紛れ込ませる高度な手法を用いています。主にイスラエルの組織を標的としており、フォレンジックによる検知を回避するように設計されています。
🔍該当判定
- Google Apps Scriptを業務ツールや自動化プログラムで利用している
- 社内ネットワークから外部へのDNS通信を制限なく許可している
- イスラエルに関連する事業展開や取引先がある
上記いずれにも該当しない → 静観でOK
✅該当時の対応
Google Apps Scriptへの不審な通信や、異常なDNSクエリの監視を強化してください。また、エンドポイントでの不審なプロセスの挙動を監視し、C2通信のパターンを分析することを推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】イラン系APT集団によるCavern C2フレームワークの通信手法について
お疲れさまです。Cavern C2に関する情報共有です。
■ 概要
イランの国家支援型アクターが使用するCavern C2フレームワークにおいて、DNS Aレコードを用いてHTTPS直接通信とGoogle Apps Scriptリレーを動的に切り替える高度な通信手法が確認されました。これにより、正当なクラウドサービスへのトラフィックに擬態し、検知を回避します。
■ 影響範囲
- 標的:主にイスラエルの組織
- 通信プロトコル:DNS, HTTPS (Google Apps Script)
■ 対応手順
1. Google Apps Script (script.google.com) への不自然なアウトバウンド通信のログを確認してください。
2. DNS Aレコードの応答に基づいた通信先の頻繁な変更など、不審なDNSトラフィックの監視を強化してください。
3. エンドポイントにおける未知のモジュールのロードや不審なネットワーク接続を監視してください。
■ 参考情報
- Kaspersky Analysis
対応優先度: 中
対応期限: 継続的な監視
お疲れさまです。Cavern C2に関する情報共有です。
■ 概要
イランの国家支援型アクターが使用するCavern C2フレームワークにおいて、DNS Aレコードを用いてHTTPS直接通信とGoogle Apps Scriptリレーを動的に切り替える高度な通信手法が確認されました。これにより、正当なクラウドサービスへのトラフィックに擬態し、検知を回避します。
■ 影響範囲
- 標的:主にイスラエルの組織
- 通信プロトコル:DNS, HTTPS (Google Apps Script)
■ 対応手順
1. Google Apps Script (script.google.com) への不自然なアウトバウンド通信のログを確認してください。
2. DNS Aレコードの応答に基づいた通信先の頻繁な変更など、不審なDNSトラフィックの監視を強化してください。
3. エンドポイントにおける未知のモジュールのロードや不審なネットワーク接続を監視してください。
■ 参考情報
- Kaspersky Analysis
対応優先度: 中
対応期限: 継続的な監視
Subject: [Intel] Advanced Communication Techniques in Cavern C2 Framework
Dear team,
We are sharing intelligence regarding the evolution of the Cavern C2 framework used by Iranian state-sponsored actors.
■ Overview
The Cavern C2 framework now utilizes a complex module that leverages DNS A-record responses to dynamically switch between direct HTTPS communication and a Google Apps Script relay. This allows the threat actor to blend C2 traffic with legitimate Google services and rotate relay IDs to evade detection.
■ Scope
- Targets: Primarily entities in Israel
- Protocols: DNS, HTTPS (via Google Apps Script)
■ Recommended Actions
1. Monitor outbound traffic to script.google.com for anomalous patterns.
2. Enhance monitoring for suspicious DNS A-record queries that may be used for C2 channel rotation.
3. Implement behavioral monitoring on endpoints to detect the loading of unauthorized C2 modules.
■ Reference
- Kaspersky Analysis
Priority: Medium
Deadline: Ongoing Monitoring
Dear team,
We are sharing intelligence regarding the evolution of the Cavern C2 framework used by Iranian state-sponsored actors.
■ Overview
The Cavern C2 framework now utilizes a complex module that leverages DNS A-record responses to dynamically switch between direct HTTPS communication and a Google Apps Script relay. This allows the threat actor to blend C2 traffic with legitimate Google services and rotate relay IDs to evade detection.
■ Scope
- Targets: Primarily entities in Israel
- Protocols: DNS, HTTPS (via Google Apps Script)
■ Recommended Actions
1. Monitor outbound traffic to script.google.com for anomalous patterns.
2. Enhance monitoring for suspicious DNS A-record queries that may be used for C2 channel rotation.
3. Implement behavioral monitoring on endpoints to detect the loading of unauthorized C2 modules.
■ Reference
- Kaspersky Analysis
Priority: Medium
Deadline: Ongoing Monitoring