CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 593

As cited

Copy frozen at (site build).

threat intel

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

Check Point Research identified Cavern Manticore, an Iran-linked advanced persistent threat group targeting Israeli government and IT organizations, operating a modular command-and-control framework built on .NET with multiple compilation formats. The framework uses uncommon binary formats (Mixed-Mode C++/CLI and Native AOT) to evade analysis tools and implements modular post-exploitation components for reconnaissance, data access, and lateral movement. Initial compromises were achieved through abuse of legitimate remote monitoring and management software already present in victim environments.

Why it matters: Israeli government, IT providers, and organizations using remote monitoring and management tools need to audit RMM deployment privileges and monitor for suspicious module loading; defenders should implement .NET runtime monitoring and recognize that low VirusTotal detection rates do not indicate safety when uncommon compilation formats are involved.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

Check Point Research identified Cavern Manticore, an Iran-linked advanced persistent threat group targeting Israeli government and IT organizations, operating a modular command-and-control framework built on .NET with multiple compilation formats. The framework uses uncommon binary formats (Mixed-Mode C++/CLI and Native AOT) to evade analysis tools and implements modular post-exploitation components for reconnaissance, data access, and lateral movement. Initial compromises were achieved through abuse of legitimate remote monitoring and management software already present in victim environments.

Why it matters: Israeli government, IT providers, and organizations using remote monitoring and management tools need to audit RMM deployment privileges and monitor for suspicious module loading; defenders should implement .NET runtime monitoring and recognize that low VirusTotal detection rates do not indicate safety when uncommon compilation formats are involved.

VendorsCheck Point
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary