Executive Summary
An Iranian state-sponsored threat cluster known as Cavern Manticore, linked to the Ministry of Intelligence and Security (MOIS), is utilizing a sophisticated, modular command-and-control (C2) framework named Cavern. This activity primarily targets Israeli IT providers and government organizations, leveraging tactical overlaps with known groups such as MuddyWater and OilRig. The campaign is notable for its use of uncommon .NET compilation formats, including Native AOT and Mixed-Mode C++/CLI, which serve as anti-analysis layers to complicate reverse engineering efforts.
The attack chain involves weaponizing trusted relationships by compromising IT service providers and using SysAid software updates to perform DLL side-loading. Once established, the adversary deploys specialized modules for Active Directory reconnaissance, database manipulation, and network tunneling. Recent intelligence also indicates parallel broad reconnaissance campaigns by affiliated actors like MuddyWater, which exploit multiple 2025 vulnerabilities in web-exposed services such as SmarterMail, Langflow, and Laravel Livewire to achieve remote code execution and data exfiltration.
Key Details
Threat Name
Cavern Manticore
Affects
SmarterMail, n8n, N-Central, Langflow, Laravel Livewire
Adversary
Cavern Manticore Other Adversaries and Aliases: MuddyWater; Lyceum; OilRig
Malware/Tools
Cavern, mhm.dll, db.dll, ode.dll, n-ten.dll, n-sws.dll
