Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
ID: 44f66440-fbb3-5f17-899d-2494e0c17662
STIX ID: report--44f66440-fbb3-5f17-899d-2494e0c17662
Feed Name: Check Point Research
**Check Point Research** documents 'Cavern Manticore', an Iran‑nexus APT using a modular .NET C2 framework (mixed IL-only, Mixed‑Mode C++/CLI, and NativeAOT builds) that abused SysAid/RMM update functionality to sideload a trojanized uxtheme.dll agent; the agent fetches NativeAOT communication and managed modules enabling file/DB/LDAP browsing, network reconnaissance, SMB credential brute‑forcing, and SOCKS5/WebSocket tunneling. The report includes detailed technical analysis of anti‑analysis techniques (per‑module AppDomain isolation, compilation-format evasion), a full command enum, extensive IOCs (file hashes, domains, mutexes, host artifacts), attribution indicators linking the activity to Iranian MOIS‑aligned actors, and recommended detections and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
