Mixed .NET Builds Make Cavern Harder to See

The hard part is not the command set. It is that the build format itself is the concealment layer, so one victim may expose only fragments of the framework and leave the rest unrecoverable. That slows triage and weakens one-off signatures because analysts have to switch toolchains and rebuild the picture from mixed .NET and native pieces. Check Point says Cavern Manticore has been using a modular .NET C2 framework against Israeli government, defense, and IT targets since early 2026. The framework is split across .NET Framework, Mixed-Mode C++/CLI, and .NET 8 Native AOT, and the observed chain also uses SysAid’s software update feature to push a DLL sideloading package that loads the Cavern agent and then pulls additional post-exploitation modules for reconnaissance, data access, tunneling, and lateral movement. The practical risk is thinner forensic visibility per host and a broader internal blast radius once trusted update or RMM paths are abused. This is the kind of design that lets an operator tailor what each victim receives, then keep moving with modules that are harder to reconstruct from any single sample.

Part of the PlainSec briefing for 2026-07-08

Sources