Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks

Iran-Linked Hackers Unleash Sophisticated Cyberattacks on Israeli Targets

A highly skilled and secretive group of hackers linked to Iran’s Ministry of Intelligence and Security (MOIS) has been conducting a series of complex cyberattacks against organizations in Israel. Dubbed “Cavern Manticore” by cybersecurity experts, this advanced persistent threat (APT) actor uses a modular command-and-control framework that is both highly adaptable and resistant to analysis.

At the heart of Cavern Manticore’s operations is a sophisticated toolset built using Microsoft’s .NET programming language. This toolchain allows the hackers to tailor their attacks to specific victims, creating a bespoke infection chain that can evade detection by even the most vigilant security teams. The framework’s anti-analysis features are particularly noteworthy, as they employ a novel approach that exploits compilation formats to hinder reverse engineering efforts.

Check Point, the cybersecurity firm that discovered Cavern Manticore, notes that this is not simply a case of obfuscation or code encryption. Instead, the hackers have cleverly leveraged the inherent complexity of .NET compilation to create an “anti-analysis layer” that requires analysts to switch between different toolchains and workflows in order to reverse-engineer the code.

Once inside a target organization’s network, Cavern Manticore’s agents establish command-and-control communication with their handlers, allowing them to fetch additional modules as needed. These modules are designed to carry out specific tasks, such as file operations, database enumeration, or even SOCKS5 proxying and WebSocket tunneling. The agents isolate each module into its own dedicated AppDomain, which is then terminated after the module is unloaded, leaving behind no analyzable assembly artifacts.

What’s particularly concerning about Cavern Manticore’s tactics is their apparent understanding of Israel’s complex IT supplier chains. In several observed cases, the hackers have moved from an initial compromised IT provider to a second-hop provider before reaching the intended target organization. This suggests that they have invested significant time and resources into mapping out these supply chain relationships.

As with many sophisticated APTs, Cavern Manticore’s operations suggest a strong understanding of both technical and social engineering tactics. In observed intrusions against Israeli targets, the hackers used remote monitoring and management (RMM) solutions for lateral movement between victims, browser-based remote desktop technologies to access environments, and built-in features like remote printing for data exfiltration.

The takeaway from this latest development is clear: organizations must remain vigilant in defending their networks against sophisticated threats like Cavern Manticore. This means staying up-to-date with the latest threat intelligence, implementing robust security controls, and investing in regular training and awareness programs to educate employees about the risks of phishing and social engineering attacks.

In particular, IT teams should focus on improving their detection capabilities by leveraging advanced threat intelligence feeds, behavior-based monitoring tools, and sandboxing solutions. By staying one step ahead of sophisticated threats like Cavern Manticore, organizations can significantly reduce their risk exposure and protect themselves against even the most complex cyberattacks.


Source: SecurityWeek — 2026-07-07