As cited
Copy frozen at (site build).
threat intel
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
Check Point Research identified Cavern Manticore, an Iran-linked advanced persistent threat group targeting Israeli government and IT organizations, operating a modular command-and-control framework built on .NET with multiple compilation formats. The framework uses uncommon binary formats (Mixed-Mode C++/CLI and Native AOT) to evade analysis tools and implements modular post-exploitation components for reconnaissance, data access, and lateral movement. Initial compromises were achieved through abuse of legitimate remote monitoring and management software already present in victim environments.
Why it matters: Israeli government, IT providers, and organizations using remote monitoring and management tools need to audit RMM deployment privileges and monitor for suspicious module loading; defenders should implement .NET runtime monitoring and recognize that low VirusTotal detection rates do not indicate safety when uncommon compilation formats are involved.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
Check Point Research identified Cavern Manticore, an Iran-linked advanced persistent threat group targeting Israeli government and IT organizations, operating a modular command-and-control framework built on .NET with multiple compilation formats. The framework uses uncommon binary formats (Mixed-Mode C++/CLI and Native AOT) to evade analysis tools and implements modular post-exploitation components for reconnaissance, data access, and lateral movement. Initial compromises were achieved through abuse of legitimate remote monitoring and management software already present in victim environments.
Why it matters: Israeli government, IT providers, and organizations using remote monitoring and management tools need to audit RMM deployment privileges and monitor for suspicious module loading; defenders should implement .NET runtime monitoring and recognize that low VirusTotal detection rates do not indicate safety when uncommon compilation formats are involved.
- Source published
- First seen by Cybersecurity Tracker