logo

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

ID: 44f66440-fbb3-5f17-899d-2494e0c17662

STIX ID: report--44f66440-fbb3-5f17-899d-2494e0c17662

Feed Name: Check Point Research

Threat Score
90/100

Date Published: 2026-07-06

Date Updated: 2026-07-23

Author: stcpresearch

...
...

Check Point Research documents 'Cavern Manticore,' an Iran-linked APT that uses a modular .NET command-and-control framework compiled across three formats (IL-only, Mixed-Mode C++/CLI, and NativeAOT) to hinder analysis; operators abused SysAid software updates/RMM to sideload a uxtheme.dll backdoor that loads a native communication module and mission-specific modules for file/system access, database browsing, LDAP/AD recon and brute-force, network reconnaissance, and SOCKS5/WebSocket tunneling. The report provides deep technical analysis, developer/infrastructure attribution cues, IOCs (hashes, domains, mutexes, host artifacts), and detection/mitigation guidance focused on monitoring for uxtheme.dll sideloading, abnormal C:\ProgramData activity, and the listed network indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.