Cavern, also known as Cav3rn, is a modular .NET-based post-exploitation command-and-control framework associated with Iranian state-linked intrusion activity targeting organizations in Israel, particularly government entities and IT service providers. The framework has been linked to the threat cluster tracked as Cavern Manticore, which has been assessed as affiliated with Iran’s Ministry of Intelligence and Security, with reported tradecraft overlaps to MuddyWater and Lyceum. Some reporting also links later Cavern-related activity to OilRig with low confidence.
Cavern is designed as an extensible toolkit composed of an agent and interchangeable modules that can be deployed according to mission requirements. Documented modules support file operations, SQL database enumeration and export, Active Directory and LDAP reconnaissance, LDAP and SMB brute-force activity, network reconnaissance and port scanning, SOCKS5 proxying, and WebSocket tunneling. The framework separates communications from operational plugins and uses multiple .NET compilation models, including .NET Framework, mixed-mode C++/CLI, and NativeAOT, to complicate analysis. Reported anti-analysis and anti-forensics features include AppDomain isolation for managed modules, runtime cleanup of working directories, export spoofing, and mixed compilation formats rather than conventional packer-based obfuscation.
Observed intrusion chains used abuse of SysAid’s software update mechanism to deliver a DLL sideloading package that executed the Cavern agent through a trojanized dependency loaded by a legitimate application. After execution, the agent established command-and-control and retrieved additional modules for follow-on activity. Operators were also reported to abuse legitimate remote monitoring and management tools, browser-based remote desktop access, and trusted provider relationships to move laterally through compromised environments and, in some cases, pivot through multiple IT providers to reach intended Israeli targets.
Cavern has continued to evolve. Newly documented communication components include modules that can dynamically choose between direct HTTPS and relayed communications through legitimate cloud services, as well as broker functionality for loading DLL components, routing messages, and supporting runtime upgrades. A related Cavern-linked implant, HollowGraph, has been assessed with high confidence as part of the framework and demonstrates the ecosystem’s emphasis on stealth by abusing Microsoft 365 calendars and the Microsoft Graph API as a covert bidirectional command-and-control and exfiltration channel, while using DNS-based credential refresh to sustain access. Across reporting, Cavern is consistently characterized as an espionage-oriented framework built for stealthy, tailored post-compromise operations in targeted environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel.
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel.
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel.
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
To remain under the radar, the threat actor creates calendar events dated May 13, 2050, with the title in specific formats. Commands and exfiltrated data are concealed within files attached to these calendar entries.
The configuration file is stored as logAzure.txt to appear as a regular log file.
The modules facilitate file operations, SQL database enumeration, Active Directory reconnaissance, LDAP brute-force attacks, network reconnaissance, and SOCKS5 proxy and WebSocket tunneling.
HTTP/HTTPS-based C2 communication... were repeatedly observed.
The main finding is a complex C2 module that uses DNS A-record responses to choose between direct HTTPS and a Google Apps Script relay for each transaction.
The main finding is a complex C2 module that uses DNS A-record responses to choose between direct HTTPS and a Google Apps Script relay for each transaction.
The modules facilitate file operations, SQL database enumeration, Active Directory reconnaissance, LDAP brute-force attacks, network reconnaissance, and SOCKS5 proxy and WebSocket tunneling.
A newly identified Windows malware sample abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command and control (C2) channel.
Researchers note that the mailbox calendars are used as a “dead drop” to store the data; hence, HollowGraph does not use traditional C2 servers to avoid detection.
Le canal C2 est classifié comme Web Service C2 dans le framework ATT&CK.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular command-and-control framework used in post-exploitation operations. It includes an agent and multiple plugins/modules for file operations, SQL database enumeration, Active Directory reconnaissance, LDAP brute-force attacks, network reconnaissance, and SOCKS5/WebSocket tunneling, while emphasizing persistence and low forensic visibility.
A larger malware/toolkit framework that HollowGraph is believed to be a variant or component of, based on command format and structure.
A malware framework assessed to be linked to HOLLOWGRAPH.
Offensive framework linked in the reporting to HollowGraph and associated by prior research with the Cavern Manticore operator.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.