Iranian Cavern Manticore Expand Operations Against Middle East Critical Infrastructure

Summary:

The Iran-affiliated threat actor Cavern Manticore is responsible for a recently discovered cyber espionage campaign that uses the advanced modular command-and-control (C2) framework Cavern (Cav3rn) to target Israeli government agencies and IT service providers. By using compromised SysAid software updates to distribute malware through DLL sideloading, the attackers exploit trusted software supply chain relationships. This enables persistent access, lateral movement, reconnaissance, and data exfiltration. To avoid detection and make reverse engineering more difficult, the framework employs sophisticated anti-analysis techniques. This campaign emphasizes the importance of strengthening supply chain security, monitoring remote management tools, and promptly remediating identified vulnerabilities. It also highlights the growing threat of state-sponsored actors exploiting trusted third-party services.

Technical Description:

The Cavern (Cav3rn) framework is modular .NET-based command-and-control (C2) platform designed to support flexible post-exploitation operations through independently loaded DLL modules. The framework separates core communication functions from operational capabilities, enabling operators to dynamically deploy only the components required for a specific objective. Identified modules provide functionality for file system operations, SQL database enumeration and manipulation, Active Directory and LDAP reconnaissance, network and SMB enumeration, port scanning, and SOCKS5/WebSocket tunneling. This modular architecture reduces the malware's footprint while improving operational flexibility and persistence.

A notable characteristic of the framework is its use of multiple .NET compilation targets within the same malware family, including standard .NET Framework assemblies, Mixed-Mode C++/CLI binaries, and .NET Native Ahead-of-Time (AOT) compiled modules. These compilation methods significantly complicate reverse engineering by requiring different analysis techniques and limiting the availability of managed metadata. Additionally, the framework incorporates a unified module dispatcher that distinguishes between native and managed components, loading native DLLs through Windows APIs while executing managed modules within isolated AppDomains. This design enhances modularity, reduces forensic artifacts, and strengthens the framework's resistance to static and dynamic analysis. The technical details of the attack campaign are discussed further below.

Delivery and Infection Chain:

The Cavern framework is delivered through the abuse of trusted relationships in the software supply chain, primarily by compromising SysAid's software update mechanism. Threat actors deploy a trojanized uxtheme.dll via DLL sideloading, allowing the malicious payload to execute in the context of a legitimate application. Once loaded, the malware retrieves additional modules from a remote command-and-control (C2) server over encrypted HTTPS or WebSocket channels, enabling the staged deployment of capabilities while minimizing the initial payload size.

The infection chain was identified as follows:

  • The threat actor abuses the SysAid software update mechanism to initiate a DLL side-loading attack, resulting in the execution of a trojanized uxtheme.dll containing the Cavern Agent.
  • The Cavern Agent loads the communication module (n-HTCommp.dll), which establishes encrypted HTTPS or WebSocket connections with the command-and-control (C2) server to receive additional payloads.
  • Based on operational requirements, the C2 server dynamically delivers modular DLL components that provide capabilities such as file management, Active Directory reconnaissance, database interaction, network discovery, tunnelling, and data exfiltration.
  • The malware maintains persistence and expands its foothold by leveraging compromised IT service providers, Remote Monitoring and Management (RMM) tools, and trusted administrative relationships to move laterally across interconnected environments.
  • Collected data is exfiltrated through encrypted C2 channels or browser-based remote desktop technologies, allowing the attackers to maintain long-term access and conduct espionage while minimizing forensic visibility.

Technical Capabilities:

The Cavern framework is built around a modular .NET architecture that separates communication functionality from post-exploitation modules. Identified components support file system operations, SQL database enumeration and manipulation, Active Directory reconnaissance, LDAP and SMB enumeration, network scanning, SOCKS5 proxying, and WebSocket tunneling. A distinguishing feature is its use of multiple .NET compilation formats, including .NET Framework, Mixed-Mode C++/CLI, and .NET Native Ahead-of-Time (AOT), which complicate reverse engineering and malware analysis. Additionally, the framework employs AppDomain isolation for managed modules and native Windows API loading for native components, enhancing operational flexibility and reducing forensic visibility.

Attribution and Evolution:

Check Point Research has attributed the campaign to Cavern Manticore, an Iran-linked threat cluster assessed to operate on behalf of Iran's Ministry of Intelligence and Security (MOIS). Researchers identified tactical overlaps with the Iranian groups MuddyWater and Lyceum, suggesting shared development practices or operational coordination. The emergence of the Cavern framework demonstrates an evolution toward more sophisticated, modular malware designed to support long-term espionage operations through adaptable post-exploitation capabilities and advanced anti-analysis techniques.

Active Campaign and Geographic Spread:

Observed activity has primarily targeted Israeli government organizations and IT service providers, with attackers leveraging trusted service-provider relationships to reach downstream victims. The broader campaign has been observed across the Middle East, with reconnaissance, credential harvesting, and data exfiltration activities targeting aviation, energy, and public sector organizations in Israel, Egypt, and the United Arab Emirates. The operators have also exploited multiple internet-facing vulnerabilities and abused Remote Monitoring and Management (RMM) solutions to facilitate lateral movement between compromised environments.

Conclusion:

The Cavern framework represents a significant advancement in Iran-linked cyber espionage capabilities, combining a highly modular design with advanced anti-analysis mechanisms and supply chain compromise tactics. Its ability to dynamically load mission-specific modules, evade traditional analysis, and exploit trusted administrative infrastructure enables threat actors to conduct covert, long-term operations against high-value targets. Organizations should prioritize patch management, strengthen supply chain security, monitor privileged remote access solutions, and develop robust detection capabilities to identify modular malware activity.

Impact:

Successful compromise enables attackers to establish persistent access, conduct extensive reconnaissance, enumerate Active Directory environments, interact with SQL databases, move laterally across networks, and exfiltrate sensitive information. The abuse of trusted software updates and managed service provider infrastructure increases the likelihood of widespread downstream compromise while reducing the effectiveness of traditional security controls. For targeted organizations, the campaign poses significant risks to the confidentiality of sensitive data, operational continuity, and overall supply chain security, particularly within government and critical infrastructure sectors.

IOC and Context Details:

Topics Details
Tactic Name Initial Access, Execution, Persistence, Defense Evasion, Discovery, Lateral Movement, Command and Control, Collection, Exfiltration
Technique Name Supply Chain Compromise, DLL Side-Loading, Command and Scripting, Active Directory Discovery, Network Service Scanning, Remote Services, Proxy, Data Exfiltration
Sub Technique Name DLL Side-Loading, Dynamic Linker Hijacking, Web Protocols (HTTPS/WebSocket) for Command and Control, SOCKS Proxy, SMB Share Enumeration, LDAP Enumeration.
Attack Type Malware
Targeted Applications SysAid, Remote Monitoring and Management (RMM) solutions, Active Directory, Microsoft SQL Server, Outlook Web Access (OWA).
Region Impacted Israel, Egypt, UAE
Industry Impacted Government, Information Technology (IT) Service Providers, Aviation, Energy, Public Sector, Critical Infrastructure.
IOC's SHA-256 Hashes:
37e123bd7998af4eae32718ce254776f36365a80ba56952593dab46f536d4066
92cae0ad7f98f51a14bcc0ee05e372ebdc29ea96ea7bd161bd3f55198767603b
5dc08bda6919a57a85e5f38b857985fa71529ca39c8299868d5a49a987e19b18
a4aa217def4c38f4ecacdf47b1cd687f60cc74c18ab75195be3c4357a790bf41
b630c96d3763182533d4fb9b614134382bd644cb02c6c1c3ade848b6ecc31e86
8e9425c0b46eeb516610ae913d13f2b3f44a023043cb099277031d4ec38a6134
0a3663648a46771a5a5423ad01e91a4e7ba825595e99fa934cb35cbb4848adc8
5394d3b220de4695f731647e3a70545f951a8912ceb0c6585efab8d6842e8b42
30cb4679c4b8599eeb3d63a551716475c6332bdc4d4b4e3de0964aadb3092a10
2cb1ad3b22db8e3666ea138fee88034a87a87cf43db3d3265a675ebf221379b0
7d586fb7f94182a8e2a0e53c7e4deb898066da029da5cd9972a94a59ca6d255a
541b1f417b9e42078c3355693a8a492b6a76048850f6549a429e0be99e6819cb
cbc9485db715e1b8cc384fe94b4cceadca4006cda8a5e28adc8848529cfafc93
ccf218189c3aadb1c761da14bfda3bae686769031e1e1b10007648bd72e34748

Domains:
hospitalinstallation[.]com
auth[.]hospitalinstallation[.]com
google[.]com[.]hospitalinstallation[.]com
adserviceupdate[.]com
hygienehistory[.]com

Host Artifacts:
MYMUTEX123HELLP
MYMUTEX123HELLP02
MYMUTEX123HELLP04
config.txt (keys: i, xd, int)
Cvn.cfg.A
Cvn.cfg.U
C:\Users\rick\Desktop\Modules\cavern\
cac.aspx
inpt / outpt working directories
.CvnC.png
.CvnA.png
.CvnR.png (JPEG-magic prefixed)

Malicious DLLs:
uxtheme.dll
n-HTCommp.dll
mhm.dll
db.dll
ode.dll
n-ten.dll
n-sws.dll
CVE CVE-2025-52691 (SmarterMail RCE)
CVE-2025-68613 (n8n RCE)
CVE-2025-9316 (N-central Session ID Generation)
CVE-2025-34291 (Langflow RCE)
CVE-2025-54068 (Laravel Livewire RCE)

Recommended Actions:

  • Apply security updates and patches promptly for internet-facing applications, including SysAid, SmarterMail, N-central, n8n, Langflow, and Laravel Livewire, to mitigate known vulnerabilities.
  • Monitor software update mechanisms and validate the integrity of updates using code signing, file integrity monitoring, and hash verification to detect unauthorized modifications.
  • Enable Endpoint Detection and Response (EDR) solutions to identify suspicious behaviors such as DLL side-loading, abnormal module loading, process injection, and unauthorized execution of native or .NET binaries.
  • Restrict and continuously monitor the use of Remote Monitoring and Management (RMM) tools and remote administration utilities, ensuring they are accessible only to authorized personnel and protected with multi-factor authentication (MFA).
  • Inspect outbound network traffic for unusual HTTPS, WebSocket, and SOCKS5 communications, and block connections to known malicious domains and command-and-control (C2) infrastructure.
  • Implement network segmentation and enforce least-privilege access controls to limit lateral movement and restrict access to critical systems, Active Directory, and sensitive databases.
  • Continuously monitor Active Directory, LDAP, SMB, and SQL Server activity for abnormal enumeration, authentication attempts, privilege escalation, and administrative actions indicative of post-exploitation.
  • Conduct regular threat hunting using updated Indicators of Compromise (IOCs), maintain comprehensive logging across endpoints and servers, and establish an incident response plan to rapidly contain and remediate suspected compromises.

Reference:

https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/