Skip to main content

Kaspersky discovered new malicious tools used in attacks on Israeli organizations

11 August 2026

New Kaspersky GReAT research has shown that Project CAV3RN, a cyberespionage toolkit used to target Israeli organizations, continues to evolve, introducing sophisticated components and tools used for communication with attackers. By abusing legitimate services - previously Outlook calendar events and in this occasion, Google Apps Script - the framework blends its network traffic with normal network activity, complicating detection for security solutions. As a result, sensitive information can be acquired by the attackers.

Continued tracking of CAV3RN in early August 2026 uncovered several previously undocumented components that expanded the framework’s communication and orchestration capabilities. The main finding is a complex command-and-control module that selects between direct HTTPS traffic and a Google Apps Script relay for each transaction. Google Apps Script is a cloud-based, low-code development platform used to automate tasks, customize features, and integrate workflows.

Furthermore, the attackers have equipped the malware’s new communication module with a backup mechanism in case its Google Apps Script channel is blocked or replaced. The attackers can publish updated connection details through a separate channel controlled by them, and the malware checks for these updates automatically and can reconnect through a new Google Apps Script deployment without replacing the malware component on the infected device. This helps the attackers maintain access when the original communication channel becomes unavailable.

Given its development pace, modular design, and operational tempo, we assess that CAV3RN will likely continue to expand and refine its arsenal. The threat actors behind this campaign are highly adaptable, seamlessly shifting from Microsoft Graph to Google Apps Script to camouflage their command-and-control traffic within legitimate, everyday network activity. This tactic of ‘living off the cloud’ highlights a deeply targeted, well-resourced, and sophisticated operation. Standard security perimeters are often blind to this type of evasion. We will continue tracking the framework closely and reporting on its activity in the wild to ensure organizations can stay one step ahead of these elusive threats,” comments Sergey Lozhkin, Head of Research Center for APAC and META at Kaspersky GReAT.

Previously, in April 2026, Kaspersky observed a major redesign of the Project CAV3RN cyberespionage framework, which evolved from a simple downloader–executor–uploader architecture into a controller-based, modular platform with a dedicated component for the malware to communicate with the attackers and an extensible plugin system. The new architecture made it easier for the operators to add new capabilities and adapt the malware over time. This redesign contributed to a significant increase in the framework's flexibility and sophistication for long-term espionage operations.

In July 2026, Kaspersky published a technical analysis that showed that the module uses Microsoft Outlook Calendar events via Microsoft Graph as its primary command-and-control channel and falls back to DNS records to recover updated configuration if Graph authentication or tenant validation fails.

To be better protected against sophisticated attacks, Kaspersky recommends:

More information is available in the report on Securelist

About the Global Research & Analysis Team
Established in 2008, Global Research & Analysis Team (GReAT) operates at the very heart of Kaspersky, uncovering APTs, cyber-espionage campaigns, major malware, ransomware and underground cyber-criminal trends across the world. Today GReAT consists of 35+ experts working globally – in Europe, Russia, Latin America, Asia and the Middle East. Talented security professionals provide company leadership in anti-malware research and innovation, bringing unrivaled expertise, passion and curiosity to the discovery and analysis of cyberthreats.

Kaspersky discovered new malicious tools used in attacks on Israeli organizations

New Kaspersky GReAT research has shown that Project CAV3RN, a cyberespionage toolkit used to target Israeli organizations, continues to evolve, introducing sophisticated components and tools used for communication with attackers. By abusing legitimate services - previously Outlook calendar events and in this occasion, Google Apps Script - the framework blends its network traffic with normal network activity, complicating detection for security solutions. As a result, sensitive information can be acquired by the attackers.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases