CYBER ESPIONAGE: Iranian Hackers Target Israeli Organizations Using Google Cloud Services

An Iranian cyber espionage campaign targeting Israeli organizations is becoming increasingly sophisticated, with attackers now exploiting legitimate Google services to conceal malicious communications, according to researchers at cybersecurity firm Kaspersky.

The campaign, known as Project CAV3RN, uses Google Apps Script — a legitimate Google development and automation service — to disguise communications between infected computers and the attackers’ command-and-control infrastructure.

By routing malicious activity through a widely used Google service, the hackers can make their traffic appear more like ordinary cloud activity rather than a connection to a suspicious server, making it more difficult for security systems to detect.

Kaspersky researchers said the attack infrastructure also includes a recovery mechanism. If one communications channel is blocked, the malware can switch to an alternative channel and obtain a new address without requiring the attackers to reinstall it on the compromised computer.

Researchers say the development reflects a broader shift from relatively simple attack infrastructure toward a modular platform that allows the hackers to add capabilities, change communication methods and maintain long-term access to compromised systems.

Kaspersky noted that similar techniques involving Microsoft Outlook and Microsoft Graph were identified in July.

The latest use of Google Apps Script demonstrates the attackers’ ability to adapt their methods and highlights the growing challenge Israeli organizations face in identifying malicious activity hidden within legitimate, everyday cloud services.

(YWN World Headquarters – NYC)

Leave a Reply

Popular Posts