{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/nativeaot/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[".NET 8","Google Apps Script"],"_cs_severities":["high"],"_cs_tags":["espionage","c2","dns","nativeaot","modular"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eProject CAV3RN is a modular espionage framework discovered targeting organizations in Israel. Recent analysis has uncovered advanced orchestration capabilities within the framework's communication module, 'GoogleService.dll', which is compiled with .NET 8 NativeAOT. This framework employs a sophisticated C2 strategy where the malware queries an adversary-controlled domain to receive DNS A-record responses. These responses dictate the communication channel, allowing the attacker to toggle between direct HTTPS connectivity and a Google Apps Script relay. The infrastructure also allows the threat actor to remotely validate and rotate Google Apps Script deployment IDs, ensuring resilient communication and evasion of static infrastructure blocks. The framework relies on a local broker that manages DLL loading, system inventory collection, and runtime upgrades, facilitating long-term persistence and modular capability expansion.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe local broker initializes and registers the communication module 'GoogleService.dll'.\u003c/li\u003e\n\u003cli\u003eThe module performs an internal handshake with the broker to verify identity using a fixed GUID.\u003c/li\u003e\n\u003cli\u003eThe malware performs a DNS A-record query to 'studiotikva.com' to receive instructions on the preferred communication channel.\u003c/li\u003e\n\u003cli\u003eDepending on the DNS response (specifically the fourth octet), the module selects either a direct HTTPS endpoint or a Google Apps Script relay.\u003c/li\u003e\n\u003cli\u003eThe module performs a deployment ID freshness check using further DNS queries to ensure the current Google Apps Script relay is valid.\u003c/li\u003e\n\u003cli\u003eThe communication module executes internal commands such as 's_version' to inventory local DLLs or 's_write' to drop payloads to disk.\u003c/li\u003e\n\u003cli\u003eData is serialized, XORed with 0xAC, Base64-encoded, and exfiltrated over the selected transport layer.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eProject CAV3RN is used in targeted espionage operations against entities in Israel. The framework's modular nature allows for customized payload delivery, system discovery, and persistent access, potentially leading to significant intellectual property theft and unauthorized information access within compromised environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy network-level blocking for the C2 domain 'studiotikva.com' and monitor for suspicious DNS queries targeting this domain.\u003c/li\u003e\n\u003cli\u003eImplement strict Egress filtering for traffic directed towards 'script.google.com' if not required for business operations, and monitor for unusual 'Google Apps Script' deployment usage.\u003c/li\u003e\n\u003cli\u003eEnable process creation logging (Event ID 1) to detect suspicious DLL loading or execution patterns by unknown binaries in user-writable directories (e.g., AppContext.BaseDirectory).\u003c/li\u003e\n\u003cli\u003eMonitor for anomalous DNS A-record traffic where the queried domain ends in '.m.studiotikva.com' or '.p.studiotikva.com'.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T10:29:11Z","date_published":"2026-08-11T10:29:11Z","id":"https://feed.craftedsignal.io/briefs/2026-08-project-cav3rn/","summary":"Project CAV3RN is a modular espionage framework targeting entities in Israel that uses a .NET NativeAOT-compiled communication module to orchestrate DNS-controlled C2 transport switching between direct HTTPS and Google Apps Script relays.","title":"Project CAV3RN Modular Espionage Framework","url":"https://feed.craftedsignal.io/briefs/2026-08-project-cav3rn/"}],"language":"en","title":"CraftedSignal Threat Feed - Nativeaot","version":"https://jsonfeed.org/version/1.1"}