A newly identified, highly sophisticated modular command-and-control (C2) framework, dubbed Cavern (also known as Cav3rn), has been uncovered, linked to an Iranian hacking group affiliated with Iran’s Ministry of Intelligence and Security (MOIS). This advanced cyber weapon has been primarily deployed against Israeli organizations, with a particular focus on critical IT providers and government sectors, signaling a significant escalation in state-sponsored cyber warfare in the region.
The discovery was made by Check Point Research, which has attributed the activity to a threat cluster they track as Cavern Manticore. According to their findings, Cavern Manticore exhibits tactical overlaps with other notorious Iranian advanced persistent threat (APT) groups, specifically MuddyWater and Lyceum. Lyceum, in turn, is widely assessed to operate as a subgroup within the broader OilRig collective, suggesting a complex and interconnected network of state-sponsored cyber operatives under the MOIS umbrella.
Unpacking the Cavern Framework: A Technical Deep Dive
The Cavern framework represents a leap in the technical capabilities of Iranian state-sponsored actors. Check Point Research characterized it as a "mature and adaptable toolset built around a shared .NET foundation." What sets Cavern apart is its innovative use of multiple compilation formats across its various components, including .NET Framework, .NET Mixed-Mode C++/CLI, and .NET Native AOT (Ahead-of-Time compilation). This multi-format approach is not merely a design choice; it functions as a potent "anti-analysis layer" that intentionally complicates the work of reverse engineers. Analysts are forced to employ diverse toolsets and engage in intricate metadata-reconstruction workflows, significantly increasing the time and resources required for threat intelligence and incident response.
The architecture of the Cavern C2 framework is meticulously designed for stealth, flexibility, and persistence. It operates through a clear division of responsibilities, utilizing a core "Cavern Agent" for initial communication and a suite of "Cavern modules" for mission-specific post-exploitation functionality. This modular design offers inherent advantages to the operators. It allows them to tailor deployments precisely to the profile of a given victim, thereby reducing their forensic footprint and making detection more challenging. Furthermore, it ensures persistent access through bespoke modules capable of performing a wide array of malicious activities, including reconnaissance of compromised networks, data theft and exfiltration, establishing covert communication tunnels, and facilitating lateral movement within the victim’s infrastructure.
The technical diversity extends to the individual components. While some modules, such as mhm.dll, db.dll, and ode.dll, are pure .NET Framework modules, others like n-HTCommp.dll, n-ten.dll, and n-sws.dll leverage Native AOT compilation. The main agent, uxtheme.dll, showcases an even higher level of sophistication by combining managed .NET code with native C++ within a single portable executable. This hybrid approach further complicates analysis and detection efforts.
At the heart of the Cavern Agent lies a unified module dispatcher. This dispatcher intelligently distinguishes between different module types based on their naming conventions. Components whose names begin with "n-" are treated as native DLLs and loaded using the LoadLibraryA Windows API, a standard method for loading dynamic-link libraries. Conversely, other modules are interpreted as managed .NET assemblies and loaded through a mechanism known as AppDomain isolation. This technique provides an additional layer of anti-forensics, as it can isolate the malicious code within its own application domain, making it harder for security tools to detect its presence or analyze its interactions with the main application. The sophisticated interplay of these compilation formats and loading mechanisms underscores the advanced capabilities of the threat actors behind Cavern.

The Attack Vector and Modus Operandi
Check Point Research’s analysis of the attack chain reveals a calculated and multi-staged approach designed to penetrate well-defended networks. The initial compromise often leverages vulnerabilities or weaknesses in trusted software, beginning with SysAid’s software update feature. The adversary weaponizes this legitimate mechanism to initiate a DLL side-loading chain. This technique involves tricking a legitimate application into loading a malicious DLL instead of a legitimate one, often by placing the malicious DLL in a location where the application expects to find its own libraries.
In the case of Cavern Manticore, this leads to the execution of a trojanized DLL, specifically uxtheme.dll, which functions as the Cavern Agent. Once executed, the Cavern Agent proceeds to load a standalone communication DLL module, identified as n-HTCommp.dll. This communication module is responsible for establishing contact with the C2 server, hospitalinstallation[.]com. Communication with the C2 server is conducted over secure channels, either HTTPS or WebSocket, allowing the agent to fetch additional post-exploitation modules on the fly and receive commands from the operators. While the specific names of all five DLL modules uncovered were not fully detailed in the report, their modular nature highlights the framework’s adaptability.
A particularly insidious aspect of Cavern Manticore’s operations is its ability to weaponize trusted relationships within the software supply chain. The observed attacks involved the threat actor initially compromising an IT provider. From this foothold, they would then pivot to a second-hop provider, eventually reaching the ultimate target organization. This method exploits the inherent trust between service providers and their clients, allowing the attackers to bypass perimeter defenses and gain access through what appears to be legitimate channels.
The attackers further abuse Remote Monitoring and Management (RMM) solutions, which are widely deployed by IT providers to manage client systems. By compromising RMM tools, the actors can move laterally between victims and deliver malicious software disguised as legitimate updates, making detection extremely difficult. Furthermore, the group demonstrates a sophisticated understanding of network environments and security controls. They have been observed leveraging browser-based remote desktop technologies to access targets of interest. In situations where standard data exfiltration methods like clipboard-based copy-paste or file-transfer capabilities are restricted, the threat actors have ingeniously abused built-in features such as remote printing to exfiltrate sensitive data, underscoring their resourcefulness and determination.
Attribution and Connections to Other Iranian APTs
The attribution of Cavern to an MOIS-affiliated group, specifically Cavern Manticore, is significant. The MOIS is Iran’s primary intelligence agency, responsible for both domestic and foreign intelligence gathering, as well as counter-espionage. Its involvement signifies state-level backing and resources, indicating a high degree of sophistication and strategic intent behind these cyber operations.
The tactical overlaps identified by Check Point Research with MuddyWater and Lyceum (a subgroup of OilRig) are crucial for understanding the broader landscape of Iranian cyber capabilities. MuddyWater, also known as Static Kitten, Mercury, and Seedworm, is a well-documented Iranian APT group primarily focused on espionage and destructive attacks against government, military, and telecommunications organizations across the Middle East, Europe, and North America. Lyceum, or Hexane, is known for targeting oil and gas companies and telecommunications providers, predominantly in the Middle East. OilRig, or APT34, is one of Iran’s most prolific and advanced cyber espionage groups, known for its extensive toolkit and long-running campaigns.

These overlaps could indicate several possibilities: shared infrastructure, common training methodologies, or even direct collaboration and resource sharing among these groups. It’s also possible that MOIS operates a centralized command structure that deploys different groups for different objectives or allows them to share intelligence and TTPs (Tactics, Techniques, and Procedures). Regardless of the exact nature of the relationship, the emergence of Cavern Manticore with its new Cavern framework suggests a continuous evolution and refinement of Iranian cyber warfare capabilities, building upon the lessons learned and tools developed by its predecessors.
Broader Geopolitical Context: The Iran-Israel Cyber Front
The unveiling of the Cavern framework and its deployment against Israeli targets unfolds against a backdrop of intense geopolitical tension and an escalating cyber conflict between Iran and Israel. The ongoing joint military operations launched by Israel and the U.S. against Iran highlight the multi-faceted nature of this rivalry, where cyber warfare plays an increasingly prominent role. Both nations have been actively engaged in cyber espionage and sabotage operations against each other for years, often targeting critical infrastructure, defense sectors, and government entities. This digital confrontation mirrors and often precedes or accompanies real-world political and military maneuvers.
Further illustrating the scale of Iranian cyber activity, the report mentions the recent extensive reconnaissance campaign by MuddyWater. This campaign involved scanning more than 12,000 internet-exposed systems, exploiting known security flaws in a range of popular applications and platforms including SmarterMail, n8n, N-central, Langflow, and Laravel Livewire. These vulnerabilities provided initial access points for the group to broaden its intelligence gathering efforts.
According to Oasis Security, MuddyWater’s operation progressed beyond mere reconnaissance and access attempts. It pivoted to targeted credential harvesting and data exfiltration attacks. The victims included high-value targets within the aviation, energy, and government sectors across the Middle East, specifically mentioning entities in Egypt, Israel, and the United Arab Emirates. The methods employed by MuddyWater in this broader operation included a combination of vulnerability exploitation, brute-force attacks against Outlook Web Access (OWA) portals, and the use of newly identified command-and-control (C2) controllers supporting multi-protocol communication. This multifaceted approach enabled confirmed exfiltration of sensitive data from compromised environments, underscoring the severe impact of these sustained cyber campaigns.
Implications for Cybersecurity and National Security
The Cavern framework represents a significant enhancement in the offensive capabilities of Iranian state-sponsored actors, posing profound implications for cybersecurity and national security, particularly for nations in the crosshairs of Iranian intelligence. The sophistication of Cavern’s anti-analysis features, including its diverse .NET compilation formats and AppDomain isolation, raises the bar for detection and forensic investigation. Security researchers and incident responders must continuously adapt their toolsets and methodologies to counteract these evolving evasion techniques.
The strategic exploitation of "trusted relationships" through supply chain attacks is perhaps one of the most concerning aspects of Cavern Manticore’s modus operandi. This method bypasses traditional perimeter defenses and highlights the vulnerability of interconnected digital ecosystems. Organizations can have robust internal security, but if a trusted third-party vendor is compromised, it can open a direct conduit for adversaries. This necessitates a radical shift in security paradigms, moving beyond solely protecting one’s own infrastructure to rigorously vetting and continuously monitoring the security posture of all supply chain partners, especially those providing critical IT services or RMM solutions.

The continued and escalating nature of cyber conflicts between nation-states, exemplified by the Iran-Israel cyber front, underscores the persistent threat of state-sponsored espionage and potential sabotage. The targeting of IT providers and government sectors is not random; it aims at acquiring intelligence, disrupting critical services, and potentially pre-positioning for future offensive operations. For targeted nations, this necessitates not only strengthening defensive capabilities but also fostering greater intelligence sharing and collaborative efforts to track, attribute, and disrupt these sophisticated threat actors.
Expert Recommendations and Future Outlook
In light of these developments, cybersecurity experts universally recommend a multi-pronged approach to bolster defenses. Organizations, particularly those in critical infrastructure, government, and IT service provision, must prioritize immediate patching of known vulnerabilities, especially those exploited by groups like MuddyWater. A robust patch management program is foundational. Beyond that, rigorous vetting and continuous security assessments of third-party vendors and supply chain partners are essential. Implementing strong access controls, multi-factor authentication (MFA) across all critical systems, and network segmentation can limit lateral movement in the event of a breach.
Monitoring for anomalous activity, particularly regarding RMM solutions and remote access tools, is crucial. Organizations should employ advanced endpoint detection and response (EDR) solutions and security information and event management (SIEM) systems capable of detecting sophisticated C2 communications and unusual file executions. Furthermore, employee training on social engineering and phishing awareness remains a critical defense layer, as human error often provides the initial foothold for such attacks.
The emergence of the Cavern framework signals that state-sponsored cyber capabilities are continually evolving, becoming more stealthy, adaptable, and resilient to detection and analysis. The digital battleground between nations is dynamic, and the development of new, bespoke toolsets like Cavern ensures that the threat landscape remains complex and challenging. As geopolitical tensions persist, the global cybersecurity community must remain vigilant, collaborative, and proactive in defending against these advanced and increasingly sophisticated threats.
