Project CAV3RN Continues DNS-Controlled Multi-Transport C2 a... - #2821
Open
carlospolop wants to merge 1 commit into
Open
Project CAV3RN Continues DNS-Controlled Multi-Transport C2 a...#2821carlospolop wants to merge 1 commit into
carlospolop wants to merge 1 commit into
Conversation
Collaborator
Author
🔗 Additional ContextOriginal Blog Post: https://securelist.com/project-cav3rn-continues/120991 Content Categories: Based on the analysis, this content was categorized under "Basic Forensic Methodology > Malware Analysis > DNS-Controlled Multi-Transport C2 and Modular DLL Brokers". Repository Maintenance:
Review Notes:
Bot Version: HackTricks News Bot v1.0 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🤖 Automated Content Update
This PR was automatically generated by the HackTricks News Bot based on a technical blog post.
📝 Source Information
🎯 Content Summary
Overview and impact
Project CAV3RN is a modular Windows cyberespionage framework used against targets in Israel. This report extends earlier analysis and documents components discovered in early August 2026. It does not describe a CVE, vulnerable third-party product, initial-access vector, or standalone exploit. Instead, it reverse-engineers two ope...
🔧 Technical Details
DNS as a C2 control plane: An implant can issue an authoritative DNS query before each command poll or result upload and encode a random nonce, transport error state, and hex-encoded client identifier in the query name. The authoritative server's A-record response can act as a compact routing instruction: a specific full address can reject the client, while the final octet can select direct HTTPS, a trusted-service relay, transaction termination, or exception handling. Tracking separate relay-ID, relay-transport, and direct-transport failure states allows server-directed failover without updating the implant.
Rotating cloud relay identifiers over DNS: Malware can hash its currently stored cloud deployment ID and compare a truncated digest against four bytes returned in an A record. On mismatch, it can reconstruct a replacement using sequential DNS answers: the first response contains a total-length byte and three data bytes, and subsequent res...
🤖 Agent Actions
Plan:
Repository review is complete. The best fit is the existing
malware-analysis.md: it already covers NativeAOT modular implants, universal exports, Base64/GZip-delivered DLL updates, and traffic decoding. I’ll extend that single page with the genuinely new techniques—DNS-per-transaction routing, DNS relay-ID rotation, Apps Script relaying, and metadata-driven DLL hot-loading—without duplicating the already documented update pattern.Implementation is complete in one existing page. I’m now validating citation numbering, Markdown structure, banned-source absence in the added diff, and repository cleanliness.
Updated:
src/generic-methodologies-and-resources/basic-forensic-methodology/malware-analysis.mdAdded technical coverage of:
Appended the Securelist article as numbered reference
[24]. Validation passed withgit diff --check; only the intended file was modified.This PR was automatically created by the HackTricks Feed Bot. Please review the changes carefully before merging.