An Iranian advanced persistent threat (APT) group has begun targeting Israeli organizations using a new command-and-control (C2) framework named Cavern. This framework's discovery reveals advanced cyber tactics aimed at Israeli IT providers and government sectors.
The Cavern C2 framework, also referred to as Cav3rn, features a modular setup with unique anti-analysis characteristics. It is built on a .NET foundation and utilizes several compilation formats, posing challenges to reverse engineers.
Cavern's components are divided into agents and modules, splitting core communication functions from post-exploitation capabilities. This division implies a sophisticated method for attackers to execute tasks post-compromise.
This development underscores evolving threats in cybersecurity for critical sectors in Israel. By employing Cavern C2, the attackers demonstrate a shift in their operational tactics, potentially affecting cybersecurity strategies for Israeli IT and government sectors.
The APT group is believed to be connected to Iran's Ministry of Intelligence and Security (MOIS). Its activities draw possible connections to the OilRig subgroup, providing insight into the organizational hierarchy and affiliation within Iranian cyber operations.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Iran-linked APT Cavern Manticore is conducting cyberattacks against Israeli organizations using a modular command-and-control framework. The framework's anti-analysis features and tailored modules demonstrate an evolving threat and advanced operational tactics, potentially impacting security strategies for targeted entities.
An Iranian hacking group linked to the MOIS has begun targeting Israeli organizations using the new Cavern C2 framework, which enables sophisticated post-exploitation functionalities. This development signifies an evolution in cyber threats against critical sectors in Israel, particularly focused on IT and government services.