Cavern Manticore is an Iran-nexus threat actor assessed to be linked to Iran’s Ministry of Intelligence and Security (MOIS). The cluster has been associated with espionage-oriented intrusions targeting Israeli organizations, with a particular focus on government entities and IT service providers. Reported tradecraft and technical overlaps connect the activity to broader Iranian operations and show similarities with MuddyWater and Lyceum, the latter also known as Hexane and SiameseKitten and often associated with OilRig. The actor is notable for abusing trusted service-provider relationships and supply-chain access to reach downstream victims. In observed operations, Cavern Manticore compromised IT providers and then pivoted through additional providers or customer relationships to access intended targets. The group has also abused legitimate remote monitoring and management tooling, browser-based remote desktop access, and remote printing features during lateral movement, operational access, and data exfiltration. A defining capability of the actor is the Cavern, or Cav3rn, modular post-exploitation framework. Cavern is built on a .NET foundation and uses a mix of .NET Framework, mixed-mode C++/CLI, and .NET Native AOT components, a design choice that complicates reverse engineering and analysis. The framework separates a central agent from interchangeable modules that can be deployed according to mission requirements. Documented module capabilities include command-and-control communications, file system operations, host information collection, DPAPI decryption, SQL database enumeration and manipulation, Active Directory and LDAP reconnaissance, credential testing, network discovery, port scanning, SMB brute force, and SOCKS5 or WebSocket-based tunneling. Cavern Manticore has been observed using SysAid software deployment and update functionality to deliver a DLL sideloading chain involving legitimate software components and a trojanized loader. After execution, the Cavern agent establishes command-and-control and retrieves additional modules on demand. The framework is designed to reduce forensic visibility through per-module isolation, in-memory loading patterns, cleanup of working directories, self-update logic, and other anti-analysis and anti-forensics measures. Communications have been reported over HTTP and WebSocket transports with custom encoding and encryption layers. The actor’s operational profile indicates a tailored, modular, and stealth-conscious intrusion set aligned with state-linked intelligence collection. High-confidence reporting places Cavern Manticore among Iranian cyber espionage activity focused on Israeli government and IT-sector targets, with infrastructure, development patterns, and tradecraft supporting that assessment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
20 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-linked threat actor conducting espionage-oriented intrusions against Israeli organizations, especially government and IT sectors, by compromising IT supply chains and abusing legitimate RMM tools for lateral movement and malware deployment via the modular Cavern/Cav3rn post-exploitation C2 framework.
Conducting cyberattacks against organizations in Israel using a modular .NET-based command-and-control framework, abusing SysAid’s software update feature for DLL sideloading, compromising IT service providers to reach downstream high-value targets, and using RMM tools and browser-based remote desktop technologies for lateral movement and data exfiltration.
Iranian-linked espionage activity targeting Israeli organizations, especially government and IT service providers, using compromised/trusted IT tools and remote management channels to deliver the modular Cavern backdoor and move through supply-chain-like trusted access paths.
An Iranian threat cluster linked to the Ministry of Intelligence and Security that deploys the Cavern modular C2 framework in attacks against Israeli organizations, primarily targeting IT providers and government sectors and leveraging supply-chain trust relationships for reconnaissance, data theft, tunneling, and lateral movement.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.