Cavern Manticore is an Iran-nexus espionage threat cluster assessed with moderate confidence to be linked to Iran’s Ministry of Intelligence and Security (MOIS). The actor has been associated with intrusions primarily targeting Israeli organizations, especially government entities and IT service providers, and has shown technical and operational overlap with MuddyWater and Lyceum, including possible ties to the OilRig ecosystem. Its operations emphasize trusted-access abuse, including compromise of IT providers, use of existing remote monitoring and management access, and multi-hop pivoting through service-provider environments to reach intended victims. The group is known for using Cavern, also referred to as Cav3rn, a modular .NET-based post-exploitation framework designed to support tailored deployments and hinder analysis. Observed components provide command-and-control, file operations, database enumeration and export, Active Directory and LDAP reconnaissance, network discovery, port scanning, SMB brute force, and SOCKS5 or WebSocket tunneling. The framework uses mixed compilation formats including .NET Framework, mixed-mode C++/CLI, and NativeAOT, along with AppDomain isolation, startup cleanup, export spoofing, and other anti-analysis measures. Intrusions have included DLL sideloading chains involving trojanized components delivered through abused software deployment workflows, as well as use of legitimate remote administration pathways for lateral movement and malware deployment. Cavern Manticore has also been linked through the Cavern framework to HOLLOWGRAPH, a stealthy espionage implant that abuses Microsoft Graph and a compromised Microsoft 365 mailbox calendar for covert bidirectional command-and-control and exfiltration. Reporting on that activity indicates a focused espionage operation against an Israeli organization and reinforces the actor’s emphasis on covert persistence, cloud abuse, and low-visibility post-compromise tradecraft. The actor’s observed behavior is consistent with intelligence collection rather than financially motivated crime or disruptive ransomware operations. Known aliases directly supported here are limited to Cavern Manticore and the associated framework name Cavern or Cav3rn; overlaps with MuddyWater and Lyceum indicate related tradecraft and possible organizational relationships rather than confirmed synonymy.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
21 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Iranian hacking crew referenced in connection with the Cavern/Cav3rn framework and the HOLLOWGRAPH malware, which abuses Microsoft Graph API and a compromised Microsoft 365 calendar as a covert two-way command-and-control channel.
Iran-nexus threat actor likely linked to the HollowGraph malware and a broader toolkit/framework.
Associated by Check Point with the Cavern framework/operator nexus tied to the HollowGraph espionage intrusion; discussed as an Iran-linked operator potentially connected to this activity.
Associated with the Cavern backdoor framework and linked with high confidence to the HOLLOWGRAPH espionage activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.