#cavernmanticore
Iran-linked hackers are using the new Cavern C2 framework to hit Israeli orgs, abusing trojanized SysAid updates and DLL side-loading for recon, lateral movement, and data theft. #Iran #Cavern #SysAid
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
An Iranian hacking group linked to MOIS has been using the modular Cavern (Cav3rn) C2 framework to target Israeli organizations, especially IT providers and government sectors. The campaign uses trojanized SysAid updates, DLL side-loading, and multiple anti-analysis .NET components to enable reconnaissance, lateral movement, and data theft. #Cavern #Cav3rn #CavernManticore #MuddyWater...
www.hendryadrian.com
July 6, 2026 at 10:30 PM
HollowGraph: la backdoor che trasforma il calendario di Microsoft 365 in un canale C2 cifrato
il blog: insicurezzadigitale.com/hollowgraph-...

#cybersecurity #apt #backdoor #cavernmanticore #cyberwar #graphapi #groupib #hollowgraph #infosec #iran #microsoft365 #spyware
July 22, 2026 at 9:02 AM
Iran-linked APT34 buries its C2 inside Outlook calendar events dated to the year 2050 - hiding in plain sight. https://intel.threadlinqs.com/threat/TL-2026-1588 #ThreatIntel #Project #Cav3rn #CavernManticore
July 21, 2026 at 9:10 AM
HollowGraph hides its C2 inside Outlook calendar events dated to the year 2050. No CVE - just stolen M365 keys. https://intel.threadlinqs.com/threat/TL-2026-1561 #ThreatIntel #HollowGraph #Cavern #CavernManticore
July 20, 2026 at 5:57 PM
HollowGraph hides its C2 in Microsoft 365 calendar invites - no attacker domains to block. https://intel.threadlinqs.com/threat/TL-2026-1555 #ThreatIntel #HollowGraph #Cavern #CavernManticore
July 20, 2026 at 1:03 PM
Check Point Research exposed Cavern Manticore, an Iran-linked threat actor using a modular .NET C2 framework with anti-analysis features and RMM abuse to target Israeli government and IT organizations. #Iran #CavernManticore #MuddyWater
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
Check Point Research tracked Cavern Manticore, an Iran-nexus threat actor targeting Israeli government and IT organizations using a modular .NET C2 framework with strong anti-analysis features and RMM abuse for initial access. The report also details related infrastructure, legacy Cav3rn samples, and multiple post-exploitation modules for reconnaissance, file access, LDAP, SQL, networking, and tunneling. #CavernManticore #MuddyWater #Lyceum #SysAid #uxtheme.dll #n-HTCommp.dll
www.hendryadrian.com
July 7, 2026 at 1:30 AM