Minacce · 84 giorni fa
Qui il punto non è il C2 in sé. È che il formato di compilazione diventa la difesa anti-analisi: prima ancora di capire cosa faccia il framework, bisogna ricostruire pezzi scritti in .NET diversi, con metadata incompleti e strumenti diversi. Per un team di triage, il risultato è una visione forense più povera e una firma meno durevole.
Check Point attribuisce a Cavern Manticore un framework modulare contro organizzazioni israeliane del settore IT, governo e difesa, osservato dall’inizio del 2026. I componenti usano .NET Framework, .NET Mixed-Mode C++/CLI e .NET 8 Native AOT; la catena vista in rete passa da SysAid e da un DLL sideloading legittimato da WinDirStat.exe per caricare l’agente e poi moduli separati per ricognizione, accesso ai dati, tunneling e movimento laterale.
Il quadro conta anche oltre questo caso: quando il delivery passa da software di gestione interno o da feature di update, la fiducia già presente nella rete viene riusata per distribuire malware in modo mirato. In ambienti con RMM e flussi di aggiornamento gestiti, la superficie reale non è un singolo backdoor, ma una piattaforma modulare che cambia profilo per vittima.
4 fonti che coprono questa storia
Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks
Researchers say the Iran-linked threat actor used an adaptable modular malware framework and compromised IT service providers to reach high-value targets in Israel.
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
Cavern agents were observed in the wild using DLL sideloading, NativeAOT modules, AppDomain unloading, and low VirusTotal detection rates.
New Iran-Nexus Hacking Group Targets Israel Government and IT Sectors
Check Point researchers have identified a new cyber adversary targeting Israeli government and IT businesses, tracked as ‘Cavern Manticore’
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework - Check Point Research
Key Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors.
Part of the PlainSec briefing for 2026-07-08