Skip to content
Iranian State-Sponsored 'Cavern' C2 Framework Targets Israeli IT and Government Sectors

Iranian State-Sponsored 'Cavern' C2 Framework Targets Israeli IT and Government Sectors

Qpulse.Quasarcybertech July 7, 2026

Attackers are weaponizing trusted IT provider relationships and RMM software to deliver malicious updates and move laterally into target environments.

Cavern Manticore, an Iranian hacking group affiliated with the Ministry of Intelligence and Security (MOIS), is utilizing a modular C2 framework called Cavern (or Cav3rn) to target Israeli organizations, specifically IT providers and government sectors. The framework is built on a .NET foundation and employs complex compilation formats—including .NET Framework, .NET Mixed-Mode C++/CLI, and .NET Native AOT—to complicate reverse engineering and forensic analysis. The attack chain begins by leveraging the software update feature of SysAid to initiate a DLL side-loading process. This leads to the execution of a trojanized DLL, 'uxtheme.dll,' which contains the Cavern Agent. The agent then loads a communication module, 'n-HTCommp.dll,' to connect to the C2 server 'hospitalinstallation[.]com' and retrieve additional post-exploitation modules. The framework includes five specific DLL modules: 'mhm.dll' for file operations, 'db.dll' for SQL database manipulation, 'ode.dll' for Active Directory reconnaissance and LDAP brute-forcing, 'n-ten.dll' for network reconnaissance and SMB brute-forcing, and 'n-sws.dll' for SOCKS5 proxy and WebSocket tunneling. The agent uses a unified module dispatcher to load these components, utilizing AppDomain isolation as an anti-forensics measure. The threat actor moves laterally by compromising IT providers and using them as a pivot point to reach intended targets, effectively weaponizing trusted supply chain relationships. Additionally, the actor abuses RMM tools, browser-based remote desktop technologies, and features like remote printing to exfiltrate data. Separately, the MuddyWater threat cluster has been conducting reconnaissance on over 12,000 internet-exposed systems, exploiting vulnerabilities in SmarterMail, n8n, N-central, Langflow, and Laravel Livewire.

This incident demonstrates a significant risk to organizations relying on third-party IT providers and RMM solutions. By compromising these trusted service providers, attackers can bypass perimeter defenses and deliver malicious software disguised as legitimate updates. Defenders must scrutinize the integrity of software update channels and monitor RMM tools for unauthorized usage or unusual lateral movement patterns. The use of advanced anti-analysis techniques, such as mixed .NET compilation targets and AppDomain isolation, indicates a high level of operational maturity. Security teams should be aware that standard forensic workflows may be insufficient to analyze these components. Furthermore, the broader reconnaissance campaign targeting internet-exposed systems like SmarterMail and N-central highlights the necessity of patching known vulnerabilities to prevent initial access.

This incident primarily targets government and IT infrastructure. However, users of IT management software should remain vigilant for unusual system behavior or unauthorized software updates.

Audit RMM tool logs for unauthorized access or unusual remote printing activity.

Monitor for connections to 'hospitalinstallation[.]com' and unusual DLL loading patterns involving 'uxtheme.dll'.

Implement strict access controls for RMM tools and verify the integrity of software update sources.

Review third-party vendor access and supply chain security policies, specifically regarding RMM and remote management software.

Advisory purposes only · QPulse Security Intelligence Platform · 2026 · Brief # 04528