logo

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

ID: 44f66440-fbb3-5f17-899d-2494e0c17662

STIX ID: report--44f66440-fbb3-5f17-899d-2494e0c17662

Feed Name: Check Point Research

Threat Score
90/100

Date Published: 2026-07-06

Date Updated: 2026-08-06

Author: stcpresearch

...
...

**Check Point Research** documents 'Cavern Manticore', an Iran‑nexus APT using a modular .NET C2 framework (mixed IL-only, Mixed‑Mode C++/CLI, and NativeAOT builds) that abused SysAid/RMM update functionality to sideload a trojanized uxtheme.dll agent; the agent fetches NativeAOT communication and managed modules enabling file/DB/LDAP browsing, network reconnaissance, SMB credential brute‑forcing, and SOCKS5/WebSocket tunneling. The report includes detailed technical analysis of anti‑analysis techniques (per‑module AppDomain isolation, compilation-format evasion), a full command enum, extensive IOCs (file hashes, domains, mutexes, host artifacts), attribution indicators linking the activity to Iranian MOIS‑aligned actors, and recommended detections and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.