Cavern, also referred to as Cav3rn, is a modular post-exploitation command-and-control framework built on .NET and used in espionage-oriented intrusions attributed to the Iran-linked threat cluster Cavern Manticore, which has been associated with Iran’s Ministry of Intelligence and Security and shows technical overlaps with MuddyWater and Lyceum. Observed operations have primarily targeted Israeli organizations, especially government entities and IT service providers, with attackers sometimes pivoting through compromised providers and trusted remote management relationships to reach downstream victims.
The framework is composed of a mixed-mode agent and interchangeable modules compiled across multiple formats, including .NET Framework, C++/CLI, and Native AOT. This heterogeneous design appears intended to complicate reverse engineering and reduce forensic visibility. The agent orchestrates module loading, separates native and managed components, isolates managed modules in dedicated application domains, and unloads them after execution. Reported anti-analysis and anti-forensics behaviors include startup cleanup, export spoofing, uncommon compilation choices, and communication encoding over HTTP or WebSocket transports.
Observed intrusion chains include abuse of SysAid software update functionality to deliver a DLL sideloading package that launches a legitimate application and causes execution of a trojanized agent component. After establishing command-and-control, the agent can retrieve additional modules on demand. Documented modules support file system operations and data collection, DPAPI decryption, SQL database enumeration and export, Active Directory and LDAP reconnaissance, network discovery, port scanning, SMB credential attacks, and SOCKS5 or WebSocket-based tunneling. In operational use, the broader intrusion set has also involved remote monitoring and management tooling, browser-based remote desktop access, and remote printing to facilitate lateral movement and exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Le framework Cavern est un C2 post-exploitation entièrement basé sur .NET ... Évolution documentée depuis un outil antérieur nommé Cav3rn (leetspeak).
Le framework Cavern est un C2 post-exploitation entièrement basé sur .NET ... Évolution documentée depuis un outil antérieur nommé Cav3rn (leetspeak).
Le framework Cavern est un C2 post-exploitation entièrement basé sur .NET ... Évolution documentée depuis un outil antérieur nommé Cav3rn (leetspeak).
40 distinct techniques documented for this family, organized by ATT&CK tactic.
Trois formats de compilation forçant l’analyste à utiliser plusieurs toolchains simultanément ... NativeAOT : résolution des API sensibles via tables de descripteurs P/Invoke
When the real WinDirStat program runs, it unknowingly loads a fake version of a Windows file called uxtheme.dll, which is actually the Cavern backdoor in disguise.
The malware also cleans up after itself, deleting most files in its working folder except what it needs to keep running. This housekeeping is a deliberate anti-forensics step.
Dedicated modules support file operations, database enumeration and manipulation, LDAP brute-force, network reconnaissance and SMB brute-force...
The attackers abuse SysAid, a remote monitoring and management platform, to push out a fake software update.
After establishing command-and-control (C&C) communication, the agent fetches additional modules based on commands received from the operator.
Le module n-HTCommp.dll implémente un dispatcher HTTP/WebSocket avec les verbes : get , send , cget , cpost , upload , ws , getws , sendws , closews
It then pulls down extra modules on demand, giving attackers tools to browse files, query databases, search directories, or tunnel deeper into the network.
T1095 — Non-Application Layer Protocol (Command and Control)
It then pulls down extra modules on demand, giving attackers tools to browse files, query databases, search directories, or tunnel deeper into the network.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Modular .NET post-exploitation C2 framework used in intrusions attributed to the Iran-linked actor Cavern Manticore. It is deployed via DLL sideloading with WinDirStat and a trojanized uxtheme.dll agent, then loads modules for HTTPS/WebSocket C2, file operations, DPAPI decryption, SQL and LDAP reconnaissance, network scanning/SMB brute force, and SOCKS5/WebSocket tunneling. It uses anti-analysis techniques including mixed compilation formats, AppDomain isolation, NativeAOT API indirection, cleanup of prior modules, and low detection rates.
A modular .NET command-and-control framework used by the Iran-linked threat actor Cavern Manticore. It separates communication from post-compromise modules and can load capabilities for file operations, database enumeration and manipulation, LDAP brute-force, network reconnaissance, SMB brute-force, and SOCKS5/WebSocket tunneling, while using multiple compilation formats and AppDomain isolation as anti-analysis measures.
A modular backdoor/framework used in Iranian-linked intrusions. It is delivered via a fake SysAid update and WinDirStat DLL sideloading using a trojanized uxtheme.dll. It supports encrypted C2 communications and on-demand modules for file browsing, database queries, directory/LDAP searches, network reconnaissance, and SOCKS5/WebSocket tunneling, while using anti-forensics cleanup and multiple build variants to hinder analysis.
A novel modular .NET-based command-and-control framework used in intrusions against Israeli organizations. It consists of a Cavern Agent and follow-on modules enabling reconnaissance, data theft, tunneling, lateral movement, file operations, database manipulation, Active Directory reconnaissance, and network scanning. It is delivered via a trojanized DLL executed through abuse of SysAid's software update feature, then retrieves additional post-exploitation modules from C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.