Research reveals: Iran is using a Google tool to attack Israel

Kaspersky researchers identified new capabilities in a campaign targeting organizations in Israel: attackers are using Google Apps Script to disguise malicious communication and are operating a recovery mechanism designed to maintain access to computers even after the communication channel is blocked.

WallaAuthor: Yinon Ben Shoshan
Source
Research reveals: Iran is using a Google tool to attack Israel
Photo: צילום: Walla.co.il

The Iranian espionage campaign Project CAV3RN, targeting organizations in Israel, continues to evolve — and this time, the attackers are moving from Microsoft's cloud services to those of Google. A new study by the GReAT team at Kaspersky reveals new components in the attack infrastructure that allow attackers to disguise malicious activity within legitimate network traffic and continue operating even when one of their communication channels is blocked.

According to Kaspersky, starting from early August 2026, researchers identified components that had not been previously documented in the CAV3RN infrastructure. The most prominent of these is a command and control module capable of choosing in real-time how to transfer data between the infected computer and the attackers — via a direct HTTPS connection or through Google Apps Script.

Google Apps Script is a legitimate Google service used for development and process automation. However, in this case, the very fact that it is a well-known and widely used service makes it a useful tool for the attackers. Instead of malicious network traffic pointing to a suspicious server that is relatively easy to flag and block, it can look like routine communication with a Google service.

This tactic is known in the cyber world as "Living off the Cloud" — using legitimate cloud infrastructures for malicious activity. From the perspective of an organization's security systems, the challenge is clear: blocking central cloud services is not necessarily a practical option, and at the same time, it is harder to separate normal business activity from the communication serving the attackers.

Blocking is not necessarily enough

However, the use of Google is only part of the upgrade. According to the researchers, CAV3RN is now also equipped with a recovery mechanism designed to allow the attackers to maintain a foothold in the corporate network over time.

If the communication channel based on Google services is blocked by security teams, the malware is capable of independently checking for updates via a separate channel and receiving a new address through which communication will be renewed. This means that blocking the address used for the attack does not necessarily remove the attackers from the infected computer, and they do not have to reinstall the malware to restore contact.

The new capabilities are part of a broader change that the infrastructure has been undergoing in recent months. As early as April 2026, Kaspersky identified a shift from a relatively simple structure of downloading and running malware to a modular platform. The new structure allows for adding components over time, changing espionage capabilities, and maintaining prolonged and quiet presence on victims' computers.

The move to Google also does not happen in a vacuum. In July, Kaspersky revealed that the campaign operators similarly exploited Microsoft Outlook and Microsoft Graph to manage communication as part of the attack. Now, according to the company, the use of Google Apps Script points to the operators' ability to switch between central cloud services and adapt their infrastructure as needed.

"The research reveals a new nature of attack, and this is what should primarily concern us," says Asaf Hazan, CTO at Kaspersky Israel. According to him, the attackers demonstrate "an exceptionally high ability to adapt," among other things by moving from Microsoft services to Google services, with the goal of disguising malicious communication within legitimate daily activity and preventing a situation where the attack is stopped the moment it is discovered.

Kaspersky estimates that the pace of development, the modular structure, and the activity of CAV3RN indicate that the infrastructure may continue to expand. From the perspective of organizations in Israel, the challenge is not only to identify malware or block a suspicious server, but to deal with an attack that intentionally tries to look like an inseparable part of their regular cloud traffic. And as the line between a legitimate service and an attack channel blurs, the work of security teams also becomes more complex.

Related News