Threats · 69 days ago
The hard part is not the command set. It is that the build format itself is the concealment layer, so one victim may expose only fragments of the framework and leave the rest unrecoverable. That slows triage and weakens one-off signatures because analysts have to switch toolchains and rebuild the picture from mixed .NET and native pieces.
Check Point says Cavern Manticore has been using a modular .NET C2 framework against Israeli government, defense, and IT targets since early 2026. The framework is split across .NET Framework, Mixed-Mode C++/CLI, and .NET 8 Native AOT, and the observed chain also uses SysAid’s software update feature to push a DLL sideloading package that loads the Cavern agent and then pulls additional post-exploitation modules for reconnaissance, data access, tunneling, and lateral movement.
The practical risk is thinner forensic visibility per host and a broader internal blast radius once trusted update or RMM paths are abused. This is the kind of design that lets an operator tailor what each victim receives, then keep moving with modules that are harder to reconstruct from any single sample.
4 sources covering this story
Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks
Researchers say the Iran-linked threat actor used an adaptable modular malware framework and compromised IT service providers to reach high-value targets in Israel.
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
Cavern agents were observed in the wild using DLL sideloading, NativeAOT modules, AppDomain unloading, and low VirusTotal detection rates.
New Iran-Nexus Hacking Group Targets Israel Government and IT Sectors
Check Point researchers have identified a new cyber adversary targeting Israeli government and IT businesses, tracked as ‘Cavern Manticore’
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework - Check Point Research
Key Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors.
Part of the PlainSec briefing for 2026-07-08