A hacker group affiliated with Iran's Ministry of Intelligence and Security (MOIS) is using a previously undisclosed, modular command and control (C2) framework called Cavern C2 (also known as Cav3rn) to target Israeli organizations.
See also: Hackers use news sites and social media to spread malware

This activity is primarily focused on IT providers and government sectors and has been attributed to a threat group monitored by Check Point Research called Cavern Manticore. This group shares some tactical similarities with MuddyWater and Lyceum, with the latter being considered a subgroup within OilRig.
The framework is described as a mature and adaptable toolset built on a common .NET foundation, using multiple compilation formats across various components, including the .NET Framework, .NET Mixed-Mode C++/CLI , and .NET Native AOT. The compilation format acts as an anti-analysis layer, complicating reverse engineering efforts.
The C2 framework components are categorized as Cavern Agent and Cavern modules, which separate responsibilities between core communication capabilities and mission-specific post-exploitation functionality. This architecture allows operators to tailor deployments based on victim profile, reduce forensic visibility, and maintain continuous access through custom modules for reconnaissance, data theft, tunneling, and lateral movement.
The attack chain documented by Check Point Research begins with SysAid, which the adversary exploits to initiate a DLL sideloading chain that leads to the execution of a modified DLL (“uxtheme.dll”) containing the Cavern Agent. The agent loads a standalone communication module DLL (“n-HTCommp.dll”) to communicate with the C2 server (“hospitalinstallation[.]com”) and retrieve additional modules after the exploit via HTTPS or WebSocket.
See also: Iranian Hackers Target US Critical Infrastructure with PLC Attacks

The framework includes various modules for specific functions:
- – mhm.dll: file operations, enumeration, file search with recursion, file management and bidirectional file transfer
- – db.dll: SQL database enumeration, queries, export and manipulation
- – ode.dll: Active Directory identification, user/group enumeration and LDAP brute-force attempts
- – n-ten.dll: network discovery, port scanning, shared enumeration, and SMB brute-force attempts –
- n-sws.dll: SOCKS5 proxy and WebSocket tunnels
A notable feature of the framework is the use of three different .NET compilation targets in its components. While mhm.dll, db.dll, and ode.dll are pure .NET Framework modules, n-HTCommp.dll, n-ten.dll, and n-sws.dll use Native AOT (Ahead-of-Time) compilation. The main agent, uxtheme.dll, combines managed .NET code with native C++ into a single executable.
Inside the agent there is a unified module dispatcher that treats components starting with 'n-' as native DLLs loaded via the Windows LoadLibraryA API , while the others are interpreted as managed .NET assemblies loaded via AppDomain isolation
The stance against context analysis is based on unusual .NET compilation formats (Mixed-Mode C++/CLI and Native AOT) that complicate reverse engineering efforts, along with per-unit AppDomain isolation as an anti-forensics measure.
The attacks orchestrated by Cavern Manticore have involved the threat actor moving from an initially compromised IT provider to a second-tier provider before finally reaching the intended target organization. This indicates their ability to exploit trust relationships in the software supply chain.
See also: Phantom Squatting: Hackers exploit AI hallucinations for phishing

This activity highlights the business value of relationships with trusted service providers, particularly where Remote Monitoring and Management (RMM) solutions are deployed. By abusing these tools, the actor can move laterally within networks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
