Iranian Cavern Manticore Targets Israeli IT and Government
Score: 8/10

Iranian Cavern Manticore Targets Israeli IT and Government

The Iranian threat actor Cavern Manticore is targeting Israeli IT providers and government sectors using the modular Cavern C2 framework and supply chain exploitation.

Executive Summary

An Iranian state-sponsored threat cluster known as Cavern Manticore, linked to the Ministry of Intelligence and Security (MOIS), is utilizing a sophisticated, modular command-and-control (C2) framework named Cavern. This activity primarily targets Israeli IT providers and government organizations, leveraging tactical overlaps with known groups such as MuddyWater and OilRig. The campaign is notable for its use of uncommon .NET compilation formats, including Native AOT and Mixed-Mode C++/CLI, which serve as anti-analysis layers to complicate reverse engineering efforts.

The attack chain involves weaponizing trusted relationships by compromising IT service providers and using SysAid software updates to perform DLL side-loading. Once established, the adversary deploys specialized modules for Active Directory reconnaissance, database manipulation, and network tunneling. Recent intelligence also indicates parallel broad reconnaissance campaigns by affiliated actors like MuddyWater, which exploit multiple 2025 vulnerabilities in web-exposed services such as SmarterMail, Langflow, and Laravel Livewire to achieve remote code execution and data exfiltration.

Key Details

Threat Name

Cavern Manticore

Affects

SmarterMail, n8n, N-Central, Langflow, Laravel Livewire

Adversary

Cavern Manticore Other Adversaries and Aliases: MuddyWater; Lyceum; OilRig

Malware/Tools

Cavern, mhm.dll, db.dll, ode.dll, n-ten.dll, n-sws.dll

Report Score

8out of 10
Quality Score
Good
IOC Quality7
TTP Details9
Detection Guidance6
Enterprise Relevance9
Clarity & Structure9
Technical Depth8

Sources