INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Iran-Nexus Hacking Group Targets Israel Government and IT Sectors
| 2026-07-06 12:25 CRITICAL HIGHExecutive Summary AI-generated
The new Iran-Nexus hacking group, tracked as 'Cavern Manticore,' has been linked to the Iranian government and is targeting Israeli government and IT organizations. This threat group shares technical overlaps with other Iranian adversaries like MuddyWater and Lyceum, two groups attributed to Iran's Ministry of Intelligence and Security. The Cavern Manticore group gained access to defense and government sectors during a US military campaign, demonstrating operational tempo and disciplined target selection. A new cyber threat has emerged linked to the Iranian government, with Check Point Research reporting that Israeli organizations have been targeted since early 2026.
Technical Mitigations AI-generated
* Implement a secure remote monitoring and management (RMM) software policy to prevent exploitation of existing vulnerabilities, such as the use of .NET compilation formats like .NET Framework, .NET Mixed-Mode C++/CLI, and .NET Native AOT.
* Regularly update and patch all RMM software to ensure that any known vulnerabilities are addressed before they can be exploited by attackers using this type of malware.
* Use a secure communication protocol, such as HTTPS or SFTP, when communicating with the attacker-controlled IIS server hosting the C2 module (cac.aspx) to prevent eavesdropping and tampering.
* Implement AppDomain isolation on all Windows systems to prevent defenders from recovering full capabilities from a compromised host by using per-module AppDomain isolation in the Cavern Manticore framework.
* Use a secure file system, such as encrypted volumes or network-attached storage (NAS), when storing sensitive data on the compromised environment to prevent unauthorized access and exfiltration of data.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation Epic FuryOperation Epic Fury
MuddyWaterMuddyWaterOilRigOilRig
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
defensedefense
governmentgovernment
Incident Timeline
2026/07/06
The threat actors used a modular C2 framework to target the same project, which was refactored and split across separate modules for improved hardening.
July 6
Threat actors used Iranian government-linked modular C2 framework to target organizations in the defense and government sectors.
Click on any entity below to view its context and source!
industry
Government
“The adversary’s ability to gain access to organizations in the defense and government sectors during the US military campaign ‘Operation Epic Fury’ demonstrates both a high operational tempo and a disciplined approach to target selection,” the researchers wrote in
a threat intelligence report
published on July 6.
target_region
United States
“The adversary’s ability to gain access to organizations in the defense and government sectors during the US military campaign ‘Operation Epic Fury’ demonstrates both a high operational tempo and a disciplined approach to target selection,” the researchers wrote in
a threat intelligence report
published on July 6.
industry
Defense
“The adversary’s ability to gain access to organizations in the defense and government sectors during the US military campaign ‘Operation Epic Fury’ demonstrates both a high operational tempo and a disciplined approach to target selection,” the researchers wrote in
a threat intelligence report
published on July 6.
campaign
Operation Epic Fury
“The adversary’s ability to gain access to organizations in the defense and government sectors during the US military campaign ‘Operation Epic Fury’ demonstrates both a high operational tempo and a disciplined approach to target selection,” the researchers wrote in
a threat intelligence report
published on July 6.
2026/07/06
Cavern Manticore exploited an older Cav3rn agent and the older mhm.dll variant, carried as configuration by the older cav3rn agent.
Click on any entity below to view its context and source!
organisation
Cavern Manticore
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework.
Cavern Manticore’s Modular C2 Infrastructure
According to Check Point, Cavern Manticore typically gains access to its targets’ IT environments by abusing existing remote monitoring and management (RMM) software.
threat_actor
OilRig
Cavern Manticore is an Iran MOIS (Ministry of Intelligence and Security)-linked actor, with links to the OilRig subgroup named
Lyceum
.
The use of victim-side infrastructure to proxy C2 traffic, combined with XOR-based obfuscation, Base64 encoding, and a fixed verb set per backdoor, is consistent with techniques we have previously observed in operations attributed to
OilRig subgroup named Lyceum
.
“The use of victim-side infrastructure to proxy C2 traffic, combined with XOR-based obfuscation, Base64 encoding, and a fixed verb set per backdoor, is consistent with techniques we have previously observed in operations attributed to
OilRig
subgroup named Lyceum,” the researchers wrote.
threat_actor
MuddyWater
Additional overlaps further support a possible Iranian nexus: the targeting of SysAid servers has been observed in past activity linked to Iranian MOIS-aligned actors, including
MuddyWater
, and this campaign similarly focused on major IT providers in Israel.
Cavern Manticore shares technical overlaps with other Iranian MOIS (Ministry of Intelligence and Security)-linked threat actors, including
MuddyWater
and
Lyceum
.
The group, tracked by the Tel Aviv-headquartered cybersecurity firm as ‘Cavern Manticore,’ shares technical overlaps with
MuddyWater
and Lyceum, two threat groups with attributed links to Iran’s Ministry of Intelligence and Security (MOIS).
Other techniques, such as the targeting of SysAid servers, overlap further support possible Iranian links with MOIS-aligned actors, including
MuddyWater
.
organisation
Conclusion
Cavern Manticore
Conclusion
Cavern Manticore
illustrates the continued evolution of Iran-nexus cyber capabilities, exposing a
mature
and
modular C2 framework
that can be rapidly adapted to new campaigns, targets, and operational requirements.
organisation
RMM
Cavern Manticore’s Modular C2 Infrastructure
According to Check Point, Cavern Manticore typically gains access to its targets’ IT environments by abusing existing remote monitoring and management (RMM) software.
The campaign further highlights the expanding role of Remote Monitoring and Management tools (RMM) as an evolution of traditional living-off-the-land techniques.
organisation
Cavern Manticore’s
Cavern Manticore’s Modular C2 Infrastructure
According to Check Point, Cavern Manticore typically gains access to its targets’ IT environments by abusing existing remote monitoring and management (RMM) software.
By decoupling its core infrastructure from mission-specific modules, Cavern Manticore’s operators gain both operational agility and durability under defensive pressure.
organisation
XOR
“The use of victim-side infrastructure to proxy C2 traffic, combined with XOR-based obfuscation, Base64 encoding, and a fixed verb set per backdoor, is consistent with techniques we have previously observed in operations attributed to
OilRig
subgroup named Lyceum,” the researchers wrote.
Component
Internal Name
Format
Role
Cavern Agent
uxtheme.dll
Mixed-Mode C++/CLI (.NET 4.7.2, IL + Native)
Core backdoor, module orchestrator
Communication Module
n-HTCommp.dll
NativeAOT (.NET 8, Native-only)
HTTPS/WebSocket transport, XOR-encrypted traffic
File Manager
mhm.dll
.NET
organisation
LDAP / Active Directory
b630c96d3763182533d4fb9b614134382bd644cb02c6c1c3ade848b6ecc31e86
n-HTCommp.dll
(communication module)
8e9425c0b46eeb516610ae913d13f2b3f44a023043cb099277031d4ec38a6134
mhm.dll
(file manager module)
0a3663648a46771a5a5423ad01e91a4e7ba825595e99fa934cb35cbb4848adc8
mhm.dll
(file manager module, older “Cav3rn” variant)
5394d3b220de4695f731647e3a70545f951a8912ceb0c6585efab8d6842e8b42
db.dll
(SQL database browser module)
30cb4679c4b8599eeb3d63a551716475c6332bdc4d4b4e3de0964aadb3092a10
ode.dll
(LDAP / Active Directory module)
2cb1ad3b22db8e3666ea138fee88034a87a87cf43db3d3265a675ebf221379b0
n-ten.dll
(network reconnaissance module)
7d586fb7f94182a8e2a0e53c7e4deb898066da029da5cd9972a94a59ca6d255a
n-sws.dll
(SOCKS5 / WebSocket tunnel module)
541b1f417b9e42078c3355693a8a492b6a76048850f6549a429e0be99e6819cb
Older
Cav3rn
agent (earlier non-modular build)
cbc9485db715e1b8cc384fe94b4cceadca4006cda8a5e28adc8848529cfafc93
Older
Cav3rn
agent (earlier non-modular build)
ccf218189c3aadb1c761da14bfda3bae686769031e1e1b10007648bd72e34748
Older
Cav3rn
HTTP module (
CAV3RN_Http_Module
)
organisation
SOCKS5 / WebSocket
b630c96d3763182533d4fb9b614134382bd644cb02c6c1c3ade848b6ecc31e86
n-HTCommp.dll
(communication module)
8e9425c0b46eeb516610ae913d13f2b3f44a023043cb099277031d4ec38a6134
mhm.dll
(file manager module)
0a3663648a46771a5a5423ad01e91a4e7ba825595e99fa934cb35cbb4848adc8
mhm.dll
(file manager module, older “Cav3rn” variant)
5394d3b220de4695f731647e3a70545f951a8912ceb0c6585efab8d6842e8b42
db.dll
(SQL database browser module)
30cb4679c4b8599eeb3d63a551716475c6332bdc4d4b4e3de0964aadb3092a10
ode.dll
(LDAP / Active Directory module)
2cb1ad3b22db8e3666ea138fee88034a87a87cf43db3d3265a675ebf221379b0
n-ten.dll
(network reconnaissance module)
7d586fb7f94182a8e2a0e53c7e4deb898066da029da5cd9972a94a59ca6d255a
n-sws.dll
(SOCKS5 / WebSocket tunnel module)
541b1f417b9e42078c3355693a8a492b6a76048850f6549a429e0be99e6819cb
Older
Cav3rn
agent (earlier non-modular build)
cbc9485db715e1b8cc384fe94b4cceadca4006cda8a5e28adc8848529cfafc93
Older
Cav3rn
agent (earlier non-modular build)
ccf218189c3aadb1c761da14bfda3bae686769031e1e1b10007648bd72e34748
Older
Cav3rn
HTTP module (
CAV3RN_Http_Module
)
organisation
AppDomain
to evade detection and complicate analysis
Cavern modules are specialized post-exploitation tools that extend functionality for tasks like reconnaissance, data theft, tunnelling and lateral movement, each compiled separately to tailor attacks per victim
To hinder forensic analysis, the framework uses per-module AppDomain isolation, preventing defenders from recovering full capabilities from a single compromised host.
The framework’s
anti-analysis
posture relies on uncommon .NET compilation formats (
Mixed-Mode C++/CLI
and
Native AOT
) that force reverse engineers into multiple toolsets and metadata-reconstruction workflows, together with per-module
AppDomain isolation
as an
anti-forensics
measure.
organisation
LDAP Module
Database enumeration, query, export, manipulation
LDAP Module
ode.dll
.NET
organisation
Command
Pure .NET Framework
(
IL-only
) modules (
mhm.dll
,
db.dll
,
ode.dll
) retain full symbol metadata, including the shared
Command.
data_breach
312 FILE_FOLDER_LIST
= 311, // 0x137 - create folder (mhm.dll)
FILE_FOLDER_LIST = 312, // 0x138 - list files / folders (mhm.dll)
SEARCH_FILE = 313, // 0x139 - search files (mhm.dll)
MOVE = 314, // 0x13A - move (mhm.dll)
LDAP_TEST = 401, // 0x191 - LDAP bind test (ode.dll)
LDAP_ALL_GROUPS = 402, // 0x192 - enumerate all groups (ode.dll)
LDAP_ALL_USERS = 403, // 0x193 - enumerate all users (ode.dll)
data_breach
313 SEARCH_FILE
= 311, // 0x137 - create folder (mhm.dll)
FILE_FOLDER_LIST = 312, // 0x138 - list files / folders (mhm.dll)
SEARCH_FILE = 313, // 0x139 - search files (mhm.dll)
MOVE = 314, // 0x13A - move (mhm.dll)
LDAP_TEST = 401, // 0x191 - LDAP bind test (ode.dll)
LDAP_ALL_GROUPS = 402, // 0x192 - enumerate all groups (ode.dll)
LDAP_ALL_USERS = 403, // 0x193 - enumerate all users (ode.dll)
data_breach
314 SEARCH_FILE
= 311, // 0x137 - create folder (mhm.dll)
FILE_FOLDER_LIST = 312, // 0x138 - list files / folders (mhm.dll)
SEARCH_FILE = 313, // 0x139 - search files (mhm.dll)
MOVE = 314, // 0x13A - move (mhm.dll)
LDAP_TEST = 401, // 0x191 - LDAP bind test (ode.dll)
LDAP_ALL_GROUPS = 402, // 0x192 - enumerate all groups (ode.dll)
LDAP_ALL_USERS = 403, // 0x193 - enumerate all users (ode.dll)
data_breach
402 SEARCH_FILE
= 311, // 0x137 - create folder (mhm.dll)
FILE_FOLDER_LIST = 312, // 0x138 - list files / folders (mhm.dll)
SEARCH_FILE = 313, // 0x139 - search files (mhm.dll)
MOVE = 314, // 0x13A - move (mhm.dll)
LDAP_TEST = 401, // 0x191 - LDAP bind test (ode.dll)
LDAP_ALL_GROUPS = 402, // 0x192 - enumerate all groups (ode.dll)
LDAP_ALL_USERS = 403, // 0x193 - enumerate all users (ode.dll)
organisation
DNS
= 803, // 0x323 - compress directory (mhm.dll)
DECOMPRESS_DIR = 804, // 0x324 - decompress directory (mhm.dll)
DECOMPRESS_FILE = 805, // 0x325 - decompress file (mhm.dll)
LIST_ARCHIVE_ITEMS = 806, // 0x326 - list archive items (mhm.dll)
DBBrowser = 901, // 0x385 - SQL database browser (db.dll)
NET_DNS_RESOLVE = 1101, // 0x44D - DNS resolve (n-ten.dll)
NET_INTERFACES = 1102, // 0x44E - network interfaces (n-ten.dll)
organisation
SOCKS5 / WebSocket Tunnel
Figure 20: The Cavern’s “n-ten.dll” module – “NetUseBrute” function → “WNetAddConnection2”.
5.5 SOCKS5 / WebSocket Tunnel – “n-sws.dll” (NativeAOT)
organisation
DPAPI
File ops, DPAPI decrypt, archive handling
SQL Browser
db.dll
.NET
organisation
db.dll
Type
{
NONE = 0, // 0x0 - sentinel / no command (Agent: uxtheme.dll)
CHANGE_ALIVE_TIME = 1, // 0x1 - update polling interval (Agent: uxtheme.dll)
INFO = 101, // 0x65 - host information (mhm.dll)
CRYPT_DECRYPT = 102, // 0x66 - DPAPI decrypt (mhm.dll)
TOKEN_INFO = 103, // 0x67 - token information (mhm.dll)
TIME_INFO = 104, // 0x68 - time information (mhm.dll)
SQL_QUERY = 201, // 0xC9 - SQL query (db.dll)
data_breach
5.2 SQL Database Browser
5.2 SQL Database Browser – “db.dll”
The
database module
implements a REST-like route dispatcher that accepts
JSON commands
with operator-supplied
SQL Server credentials
passed through
pseudo-HTTP
headers.
organisation
SMB
Net recon, port scan, share enum, SMB brute-force
Tunnel Module
n-sws.dll
NativeAOT (.NET 8, Native-only)
organisation
Tunnel Module
Net recon, port scan, share enum, SMB brute-force
Tunnel Module
n-sws.dll
NativeAOT (.NET 8, Native-only)
organisation
IL + Native
Component
Internal Name
Format
Role
Cavern Agent
uxtheme.dll
Mixed-Mode C++/CLI (.NET 4.7.2, IL + Native)
Core backdoor, module orchestrator
Communication Module
n-HTCommp.dll
NativeAOT (.NET 8, Native-only)
HTTPS/WebSocket transport, XOR-encrypted traffic
File Manager
mhm.dll
.NET
organisation
Communication Module
Component
Internal Name
Format
Role
Cavern Agent
uxtheme.dll
Mixed-Mode C++/CLI (.NET 4.7.2, IL + Native)
Core backdoor, module orchestrator
Communication Module
n-HTCommp.dll
NativeAOT (.NET 8, Native-only)
HTTPS/WebSocket transport, XOR-encrypted traffic
File Manager
mhm.dll
.NET
organisation
HTTPS/WebSocket
Component
Internal Name
Format
Role
Cavern Agent
uxtheme.dll
Mixed-Mode C++/CLI (.NET 4.7.2, IL + Native)
Core backdoor, module orchestrator
Communication Module
n-HTCommp.dll
NativeAOT (.NET 8, Native-only)
HTTPS/WebSocket transport, XOR-encrypted traffic
File Manager
mhm.dll
.NET
data_breach
5.1 File Manager
5.1 File Manager – “mhm.dll”
The
file manager module
implements the broadest command surface across three of the
enum
blocks (the
1xx
information
block
101-104
, the
3xx
file
/
directory
block
301-314
, and the
8xx
archive
block
801-806
): host information collection, DPAPI decryption, drive/file/directory enumeration, recursive file search with content matching, GZip+Base64 file transfer in both directions, ZIP archive creation/extraction, and file/directory manipulation.
financial
314 directory block
5.1 File Manager – “mhm.dll”
The
file manager module
implements the broadest command surface across three of the
enum
blocks (the
1xx
information
block
101-104
, the
3xx
file
/
directory
block
301-314
, and the
8xx
archive
block
801-806
): host information collection, DPAPI decryption, drive/file/directory enumeration, recursive file search with content matching, GZip+Base64 file transfer in both directions, ZIP archive creation/extraction, and file/directory manipulation.
organisation
API
An
older variant
of
mhm.dll
retains
legacy
“
Cav3rn
”
naming artifacts
in its static configuration: file extensions
.CvnC.png
,
.CvnA.png
,
.CvnR.png
for command, API, and result files, respectively, a config filename
Cvn.cfg
, a hardcoded page name
cac.aspx
, and embedded JPEG header magic bytes.
organisation
JPEG
An
older variant
of
mhm.dll
retains
legacy
“
Cav3rn
”
naming artifacts
in its static configuration: file extensions
.CvnC.png
,
.CvnA.png
,
.CvnR.png
for command, API, and result files, respectively, a config filename
Cvn.cfg
, a hardcoded page name
cac.aspx
, and embedded JPEG header magic bytes.
infrastructure
3.6
3.6 Agent Self-Commands
The agent handles
six built-in self-commands
before reaching the module dispatcher:
Command
Action
001
Update polling interval
002
GZip+Base64 module update (including self-update of
uxtheme.dll
)
003
Toggle debug logging
004
Activate WebSocket communication mode
005
Close WebSocket connection
006
Reconnect WebSocket
3.7 Startup Cleanup as Anti-Forensics
Newer agent builds perform aggressive directory cleanup on first startup: they enumerate all files and subdirectories in the working directory and
delete everything except
the
Communication Module
(
n-HTCommp.dll
), the
configuration file
(
config.txt
), and
log
files.
infrastructure
3.7
3.6 Agent Self-Commands
The agent handles
six built-in self-commands
before reaching the module dispatcher:
Command
Action
001
Update polling interval
002
GZip+Base64 module update (including self-update of
uxtheme.dll
)
003
Toggle debug logging
004
Activate WebSocket communication mode
005
Close WebSocket connection
006
Reconnect WebSocket
3.7 Startup Cleanup as Anti-Forensics
Newer agent builds perform aggressive directory cleanup on first startup: they enumerate all files and subdirectories in the working directory and
delete everything except
the
Communication Module
(
n-HTCommp.dll
), the
configuration file
(
config.txt
), and
log
files.
organisation
Command
Action
3.6 Agent Self-Commands
The agent handles
six built-in self-commands
before reaching the module dispatcher:
Command
Action
001
Update polling interval
002
GZip+Base64 module update (including self-update of
uxtheme.dll
)
003
Toggle debug logging
004
Activate WebSocket communication mode
005
Close WebSocket connection
006
Reconnect WebSocket
3.7 Startup Cleanup as Anti-Forensics
Newer agent builds perform aggressive directory cleanup on first startup: they enumerate all files and subdirectories in the working directory and
delete everything except
the
Communication Module
(
n-HTCommp.dll
), the
configuration file
(
config.txt
), and
log
files.
organisation
Reconnect WebSocket
3.6 Agent Self-Commands
The agent handles
six built-in self-commands
before reaching the module dispatcher:
Command
Action
001
Update polling interval
002
GZip+Base64 module update (including self-update of
uxtheme.dll
)
003
Toggle debug logging
004
Activate WebSocket communication mode
005
Close WebSocket connection
006
Reconnect WebSocket
3.7 Startup Cleanup as Anti-Forensics
Newer agent builds perform aggressive directory cleanup on first startup: they enumerate all files and subdirectories in the working directory and
delete everything except
the
Communication Module
(
n-HTCommp.dll
), the
configuration file
(
config.txt
), and
log
files.
organisation
Anti-Forensics
Newer
3.6 Agent Self-Commands
The agent handles
six built-in self-commands
before reaching the module dispatcher:
Command
Action
001
Update polling interval
002
GZip+Base64 module update (including self-update of
uxtheme.dll
)
003
Toggle debug logging
004
Activate WebSocket communication mode
005
Close WebSocket connection
006
Reconnect WebSocket
3.7 Startup Cleanup as Anti-Forensics
Newer agent builds perform aggressive directory cleanup on first startup: they enumerate all files and subdirectories in the working directory and
delete everything except
the
Communication Module
(
n-HTCommp.dll
), the
configuration file
(
config.txt
), and
log
files.
infrastructure
002 GZip+Base64
3.6 Agent Self-Commands
The agent handles
six built-in self-commands
before reaching the module dispatcher:
Command
Action
001
Update polling interval
002
GZip+Base64 module update (including self-update of
uxtheme.dll
)
003
Toggle debug logging
004
Activate WebSocket communication mode
005
Close WebSocket connection
006
Reconnect WebSocket
3.7 Startup Cleanup as Anti-Forensics
Newer agent builds perform aggressive directory cleanup on first startup: they enumerate all files and subdirectories in the working directory and
delete everything except
the
Communication Module
(
n-HTCommp.dll
), the
configuration file
(
config.txt
), and
log
files.
infrastructure
5.5
The Communication Module – “n-HTCommp.dll”
The communication module is compiled as a
NativeAOT
.NET 8 DLL (~
5.5 MB
, with about
21k stripped
framework functions) and exposes a single operational export,
get_version
.
organisation
The Communication Module
The Communication Module – “n-HTCommp.dll”
The communication module is compiled as a
NativeAOT
.NET 8 DLL (~
5.5 MB
, with about
21k stripped
framework functions) and exposes a single operational export,
get_version
.
data_breach
5.5 MB
The Communication Module – “n-HTCommp.dll”
The communication module is compiled as a
NativeAOT
.NET 8 DLL (~
5.5 MB
, with about
21k stripped
framework functions) and exposes a single operational export,
get_version
.
organisation
HTTPS
The
modern framework
collapses both halves into
n-HTCommp.dll
with direct
HTTPS
/
WebSocket
.
organisation
ASP.NET
These artifacts point to an
earlier webshell-style transport layer
(the HTTP side fronted by an ASP.NET page on a separate IIS server, invoked by the
older
Cav3rn
HTTP module
covered in
Section 5
, not by this module or by the older Cav3rn agent itself) that was
retired
when the framework
evolved
from “
Cav3rn
” to “
Cavern
” and moved to the
n-HTCommp.dll
native communication module.
Check Point noted that the majority of observed samples of Cavern Manticore’s C2 framework score zero or very low detection rates on VirusTotal, showing how adept the group is at evading traditional security measures through advanced evasion techniques.
Technical Overlaps with Other Iranian Adversaries
During their analysis, Check Point researchers identified a communication module (CAV3RN_Http_Module) that uses a webshell-style ASP.NET handler, cac.aspx, hosted on a separate IIS server at one of two attacker-controlled or attacker-deployed domains and used as the command-and-control endpoint.
organisation
NET_PORT_SCN
The newer framework adds commands (
LDAP_BRUTE
,
CRYPT_DECRYPT
, archive ops and the
NET_PORT_SCN
block), retires the
webshell
+
steganography
transport in favor of
n-HTCommp.dll
, and splits the codebase across three different compilation formats – a
refactor of the same project
, not a rewrite.
organisation
DLL
The recovered execution chain
begins
with
SysAid’s
software update
feature, which the actor leverages to deploy a
WinDirStat DLL sideloading
package to
C:\ProgramData\WinDir\WinDirStat.exe
.
infrastructure
Windows
The Cavern Agent
3.1 UxTheme Facade and Side-Load Trigger
The
Cavern Agent
is compiled as a
64-bit Mixed-Mode C++/CLI DLL
named
uxtheme.dll
and exports 83 functions that mimic the legitimate Windows theming library.
Every
HTTP-based verb
sends a
fixed Microsoft Edge
User-Agent
(
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 Edg/146.0.0.0
), and the two
C2-bound verbs
(
get
and
send
) additionally attach a custom
X-User-token
header whose value is the
agent ID
with the literal suffix
00
appended.
It resolves its
security-sensitive
Windows APIs at
runtime
through
P/Invoke
descriptor tables, which keep them
out of the PE import
table.
infrastructure
5.0
Every
HTTP-based verb
sends a
fixed Microsoft Edge
User-Agent
(
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 Edg/146.0.0.0
), and the two
C2-bound verbs
(
get
and
send
) additionally attach a custom
X-User-token
header whose value is the
agent ID
with the literal suffix
00
appended.
infrastructure
10.0
Every
HTTP-based verb
sends a
fixed Microsoft Edge
User-Agent
(
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 Edg/146.0.0.0
), and the two
C2-bound verbs
(
get
and
send
) additionally attach a custom
X-User-token
header whose value is the
agent ID
with the literal suffix
00
appended.
infrastructure
537.36
Every
HTTP-based verb
sends a
fixed Microsoft Edge
User-Agent
(
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 Edg/146.0.0.0
), and the two
C2-bound verbs
(
get
and
send
) additionally attach a custom
X-User-token
header whose value is the
agent ID
with the literal suffix
00
appended.
infrastructure
146.0.0
Every
HTTP-based verb
sends a
fixed Microsoft Edge
User-Agent
(
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 Edg/146.0.0.0
), and the two
C2-bound verbs
(
get
and
send
) additionally attach a custom
X-User-token
header whose value is the
agent ID
with the literal suffix
00
appended.
organisation
Microsoft Edge
Every
HTTP-based verb
sends a
fixed Microsoft Edge
User-Agent
(
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 Edg/146.0.0.0
), and the two
C2-bound verbs
(
get
and
send
) additionally attach a custom
X-User-token
header whose value is the
agent ID
with the literal suffix
00
appended.
organisation
Win64
Every
HTTP-based verb
sends a
fixed Microsoft Edge
User-Agent
(
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 Edg/146.0.0.0
), and the two
C2-bound verbs
(
get
and
send
) additionally attach a custom
X-User-token
header whose value is the
agent ID
with the literal suffix
00
appended.
organisation
KHTML
Every
HTTP-based verb
sends a
fixed Microsoft Edge
User-Agent
(
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 Edg/146.0.0.0
), and the two
C2-bound verbs
(
get
and
send
) additionally attach a custom
X-User-token
header whose value is the
agent ID
with the literal suffix
00
appended.
infrastructure
3.2
3.2 C2 Polling Loop
Upon invocation,
EnableThemeDialogTexture
creates a singleton mutex (
MYMUTEX123HELLP02
or
MYMUTEX123HELLP04
, depending on the build), initializes the local configuration from
config.txt
, and enters an infinite polling loop.
infrastructure
3.8
3.8 Variant Evolution
Three agent builds were recovered, showing
clear iterative
development:
Attribute
Oldest Build
Build
02
Build
04
Mutex
MYMUTEX123HELLP
MYMUTEX123HELLP02
MYMUTEX123HELLP04
C2 Domain
auth.hospitalinstallation.com
google.com.hospitalinstallation.com
google.com.hospitalinstallation.com
Config Storage
id.txt
(plain 7-char ID)
config.txt
(JSON)
config.txt
(JSON)
Self-Commands
001-003
001-006
(adds WebSocket)
001-006
Cleanup
None
Working-dir wipe
Working-dir wipe
Debug Default
true
false
true
4.
organisation
Working-dir
3.8 Variant Evolution
Three agent builds were recovered, showing
clear iterative
development:
Attribute
Oldest Build
Build
02
Build
04
Mutex
MYMUTEX123HELLP
MYMUTEX123HELLP02
MYMUTEX123HELLP04
C2 Domain
auth.hospitalinstallation.com
google.com.hospitalinstallation.com
google.com.hospitalinstallation.com
Config Storage
id.txt
(plain 7-char ID)
config.txt
(JSON)
config.txt
(JSON)
Self-Commands
001-003
001-006
(adds WebSocket)
001-006
Cleanup
None
Working-dir wipe
Working-dir wipe
Debug Default
true
false
true
4.
organisation
Debug Default
3.8 Variant Evolution
Three agent builds were recovered, showing
clear iterative
development:
Attribute
Oldest Build
Build
02
Build
04
Mutex
MYMUTEX123HELLP
MYMUTEX123HELLP02
MYMUTEX123HELLP04
C2 Domain
auth.hospitalinstallation.com
google.com.hospitalinstallation.com
google.com.hospitalinstallation.com
Config Storage
id.txt
(plain 7-char ID)
config.txt
(JSON)
config.txt
(JSON)
Self-Commands
001-003
001-006
(adds WebSocket)
001-006
Cleanup
None
Working-dir wipe
Working-dir wipe
Debug Default
true
false
true
4.
organisation
Mutex
Network
Indicator
Type
hospitalinstallation[.]com
Parent domain
auth[.]hospitalinstallation[.]com
C2 (older agent)
google[.]com[.]hospitalinstallation[.]com
C2 (newer agents)
adserviceupdate[.]com
C2 domain invoked by the older
Cav3rn
HTTP module at
; part of the older
Cav3rn
agent config
hygienehistory[.]com
C2 domain invoked by the older
Cav3rn
HTTP module at
; part of the older
Cav3rn
agent config
Host Artifacts
Indicator
Context
MYMUTEX123HELLP
/
MYMUTEX123HELLP02
/
MYMUTEX123HELLP04
Mutex names
config.txt
with keys
i
,
xd
,
int
Agent configuration
Cvn.cfg.
organisation
Cvn.cfg
Network
Indicator
Type
hospitalinstallation[.]com
Parent domain
auth[.]hospitalinstallation[.]com
C2 (older agent)
google[.]com[.]hospitalinstallation[.]com
C2 (newer agents)
adserviceupdate[.]com
C2 domain invoked by the older
Cav3rn
HTTP module at
; part of the older
Cav3rn
agent config
hygienehistory[.]com
C2 domain invoked by the older
Cav3rn
HTTP module at
; part of the older
Cav3rn
agent config
Host Artifacts
Indicator
Context
MYMUTEX123HELLP
/
MYMUTEX123HELLP02
/
MYMUTEX123HELLP04
Mutex names
config.txt
with keys
i
,
xd
,
int
Agent configuration
Cvn.cfg.
infrastructure
3.5
3.5 Module Versioning and Self-Update
Cavern implements a
numbered DLL versioning scheme
.
organisation
WebSocket
SOCKS5 proxy, WebSocket/WSS tunneling
2.
organisation
Content-Disposition
[]
and
PageName = "cac.aspx"
constants the agent carries,
POSTs
s=<timestamp>&id=<AgentID>&q=<XOR+Base32 telemetry>
to
, and expects a response whose body starts with a fixed
21-byte JPEG magic header
and whose
Content-Disposition: filename=
value is
XOR+Base32-encrypted
with the
AgentID
, then drops the carved payload into the same local
inpt\
directory the agent reads from.
data_breach
21 byte
[]
and
PageName = "cac.aspx"
constants the agent carries,
POSTs
s=<timestamp>&id=<AgentID>&q=<XOR+Base32 telemetry>
to
, and expects a response whose body starts with a fixed
21-byte JPEG magic header
and whose
Content-Disposition: filename=
value is
XOR+Base32-encrypted
with the
AgentID
, then drops the carved payload into the same local
inpt\
directory the agent reads from.
organisation
Attribution
During
Attribution
During our analysis of an
older Cavern Manticore
toolset, we identified a communication module (
CAV3RN_Http_Module
) that uses a webshell-style ASP.NET handler,
cac.aspx
, hosted on a separate IIS server at one of two attacker-controlled or attacker-deployed domains and used as the command-and-control endpoint.
organisation
VirusTotal
Check Point noted that the majority of observed samples of Cavern Manticore’s C2 framework score zero or very low detection rates on VirusTotal, showing how adept the group is at evading traditional security measures through advanced evasion techniques.
Technical Overlaps with Other Iranian Adversaries
During their analysis, Check Point researchers identified a communication module (CAV3RN_Http_Module) that uses a webshell-style ASP.NET handler, cac.aspx, hosted on a separate IIS server at one of two attacker-controlled or attacker-deployed domains and used as the command-and-control endpoint.
In malware-engine coverage, the majority of observed samples score
zero
or
very low detection
rates on VirusTotal.
organisation
Technical Overlaps with Other Iranian Adversaries
Check Point noted that the majority of observed samples of Cavern Manticore’s C2 framework score zero or very low detection rates on VirusTotal, showing how adept the group is at evading traditional security measures through advanced evasion techniques.
Technical Overlaps with Other Iranian Adversaries
During their analysis, Check Point researchers identified a communication module (CAV3RN_Http_Module) that uses a webshell-style ASP.NET handler, cac.aspx, hosted on a separate IIS server at one of two attacker-controlled or attacker-deployed domains and used as the command-and-control endpoint.
financial
702 SRV_RESET
= 602, // 0x25A - registry delete (not in modular set; older Cav3rn)
REG_QRY_SUBKEYS = 603, // 0x25B - registry query subkeys (not in modular set; older Cav3rn)
REG_QRY_VALUE = 604, // 0x25C - registry query value (not in modular set; older Cav3rn)
SRV_LIST = 701, // 0x2BD - list services (not in modular set; older Cav3rn)
SRV_RESET = 702, // 0x2BE - reset service (not in modular set; older Cav3rn)
SRV_START = 703, // 0x2BF - start service (not in modular set; older Cav3rn)
SRV_STOP = 704, // 0x2C0 - stop service (not in modular set; older Cav3rn)
GZ_READ = 801, // 0x321 - GZip read (download)
organisation
P/Invoke Target
A selection of the most
security-relevant
ones is shown below:
P/Invoke Target
Library
Purpose
WNetAddConnection2
mpr.dll
Map network drive with credentials
WNetCancelConnection2
mpr.dll
Unmap network drive
WNetOpenEnum
/
WNetEnumResource
mpr.dll
Enumerate network resources
NetUserEnum
/
NetUserGetInfo
netapi32.dll
User enumeration
NetLocalGroupEnum
/
GetMembers
netapi32.dll
Local group enumeration
NetServerEnum
netapi32.dll
Domain computer discovery
NetShareEnum
netapi32.dll
Share enumeration
NetWkstaGetInfo
netapi32.dll
Domain/workstation info
The
NetUseBrute
function iterates over
operator-supplied credential
pairs, calling
WNetAddConnection2
against a target share with each pair and immediately disconnecting successful connections via
WNetCancelConnection2
, which gives the operator an
SMB-based credential spraying primitive
.
organisation
GetMembers
A selection of the most
security-relevant
ones is shown below:
P/Invoke Target
Library
Purpose
WNetAddConnection2
mpr.dll
Map network drive with credentials
WNetCancelConnection2
mpr.dll
Unmap network drive
WNetOpenEnum
/
WNetEnumResource
mpr.dll
Enumerate network resources
NetUserEnum
/
NetUserGetInfo
netapi32.dll
User enumeration
NetLocalGroupEnum
/
GetMembers
netapi32.dll
Local group enumeration
NetServerEnum
netapi32.dll
Domain computer discovery
NetShareEnum
netapi32.dll
Share enumeration
NetWkstaGetInfo
netapi32.dll
Domain/workstation info
The
NetUseBrute
function iterates over
operator-supplied credential
pairs, calling
WNetAddConnection2
against a target share with each pair and immediately disconnecting successful connections via
WNetCancelConnection2
, which gives the operator an
SMB-based credential spraying primitive
.
organisation
SysAid
Note:
SysAid was not compromised, and no SysAid vulnerability was involved.
Once it has established initial access, the threat actor enables a SysAid’s software update which leads to installing malicious assets on the targeted environment.
organisation
CPR
CPR
observed a
modular C2 framework
in the wild, with all samples built on top of
.NET
but compiled into different output formats.
organisation
Cavern
These components are used as
Cavern agent
and
Cavern modules
.
The framework is made of two main components tracked by Check Point as Cavern agent and Cavern modules:
Cavern agent is the persistent backdoor that handles core communication with the attackers’ servers, using multiple .NET compilation formats (.NET Framework, .NET
organisation
Remote Monitoring and Management
In multiple observed intrusions, the
initial foothold
was achieved through abuse of existing Remote Monitoring and Management (
RMM
) software deployed in the targeted organization.
organisation
Cavern Modules Evade
Figure 1: Cavern Modules Evade Malware Engines.
organisation
Anti-Analysis
Three Compilation Formats as Anti-Analysis
The most distinctive architectural decision in
Cavern
is the deliberate use of
three different .NET compilation targets
across its components.
organisation
PE
Security-sensitive
P/Invoke
calls to
APIs
like
WNetAddConnection2
,
NetShareEnum
, or
NetLocalGroupGetMembers
are resolved through runtime descriptor tables instead of appearing in the PE import table, which
hides
the module’s real capabilities from import-based triage.
organisation
NativeAOT
To pull useful metadata back out of the NativeAOT samples, we ported Washi’s Ghidra NativeAOT plugin (
ghidra-nativeaot
; write-up:
organisation
Washi
To pull useful metadata back out of the NativeAOT samples, we ported Washi’s Ghidra NativeAOT plugin (
ghidra-nativeaot
; write-up:
organisation
PDB
8.0.25 NativeAOT win-x64 “
coverage
” DLL (compiled with PDB) that deliberately exercises the same .NET runtime and class library code the
Cavern
samples rely on, and generated
IDA FLIRT signatures
from it.
organisation
Custom AppDomain Isolation
3.3 Custom AppDomain Isolation with Post-Execution Unload
One of the most technically interesting mechanisms in the Cavern Agent is its module hosting strategy.
infrastructure
3.3 Custom AppDomain Isolation
3.3 Custom AppDomain Isolation with Post-Execution Unload
One of the most technically interesting mechanisms in the Cavern Agent is its module hosting strategy.
organisation
Assembly
Rather than loading .NET modules into the default
AppDomain
via
Assembly.
organisation
IntPtr
if (fileName.StartsWith("n-"))
{
// Native module path (NativeAOT compiled)
IntPtr hModule = LoadLibraryA(resolvedPath);
if (hModule == IntPtr.
organisation
0x0074
For
"get"
, the three UTF-16 characters
g
(
0x0067
),
e
(
0x0065
) and
t
(
0x0074
) become the constants
0x650067
and
0x740065
that show up in the comparison.
organisation
POST
no
no
yes
no
Operator-driven POST to an arbitrary URL
upload
HTTP POST
multipart/form-data
args[0]
(raw URL), file
args[1]
from disk as form field
file
(
application/octet-stream
)
organisation
UA
Third, the
User-Agent
header
is fixed
across every
HTTP verb
, including the operator-driven ones, which
makes the UA itself a stable host artifact for detection
.
organisation
Post-Exploitation Modules
Post-Exploitation Modules
All
Cavern modules
, regardless of
compilation format
, share a uniform interface contract: the
agent
invokes
get_version(List<string> args)
for
managed
modules or
get_version(wchar_t* args)
for
native
modules.
organisation
IOC
The three hashes (
Cav3rn
-era samples) are listed in the
IOC section
as the
older
Cav3rn
agent
(two near-identical builds) and the
older
Cav3rn
HTTP module
; the rest of this publication stays focused on the
modular generation
actually used in the intrusion.
organisation
CryptDecrypt
The
CryptDecrypt
function takes a
Base64-encoded
DPAPI-protected
blob, calls
ProtectedData.
organisation
ProtectedData
The
CryptDecrypt
function takes a
Base64-encoded
DPAPI-protected
blob, calls
ProtectedData.
organisation
SQL
It supports
SQL database enumeration
,
query
,
export
, and
manipulation
.
organisation
DN
It auto-discovers the LDAP server and base DN from
LDAP://RootDSE
when not explicitly supplied, performs paged searches with a page size of 1,000, and always accepts TLS certificates without validation.
organisation
TLS
It auto-discovers the LDAP server and base DN from
LDAP://RootDSE
when not explicitly supplied, performs paged searches with a page size of 1,000, and always accepts TLS certificates without validation.
organisation
WSS
The
tunnel module
implements a full
SOCKS5 proxy
and
WebSocket
/
WSS tunnel
in both
server
and
client
modes.
organisation
LINQ
Boilerplate such as the JSON formatting, the LINQ-heavy collection handling, and the standard P/Invoke signatures could easily have been drafted or completed with a model.
organisation
hospitalinstallation[.]com
Finally, WHOIS analysis of the root domain observed in the Cavern Manticore campaign, hospitalinstallation[.]com, showed that it was registered through Fars Data, an Iranian hosting provider.
organisation
Fars Data
Finally, WHOIS analysis of the root domain observed in the Cavern Manticore campaign, hospitalinstallation[.]com, showed that it was registered through Fars Data, an Iranian hosting provider.
organisation
Protections
Check Point Threat Emulation
Protections
Check Point Threat Emulation
and
Harmony Endpoint
provide comprehensive coverage of this attack and protect against threats described in this report.
data_breach
3 MB binary
The result is usually a 3-6 MB binary with
thousands of stripped
framework functions, a
.managed
executable section, and a
hydrated
BSS-like section where string objects are materialized only at runtime.
financial
1 tool
Any automated analysis tool that invokes ordinal
#1
, or any other default export, will observe only inert DLL loading behavior and conclude the sample is benign.
financial
20 export ordinal
The real backdoor personality sits entirely behind export ordinal
#20
(
0x14
).
financial
601 Cav3rn
= 502, // 0x1F6 - list processes (not in modular set; older Cav3rn)
REG_ADD = 601, // 0x259 - registry add (not in modular set; older Cav3rn)
REG_DEL
infrastructure
21 loaded API descriptors
Static analysis of the P/Invoke resolution data recovered
21 dynamically-loaded
API descriptors.
organisation
Check Point
Check Point researchers also observed the group deploying a previously undocumented modular command-and-control (C2) infrastructure.
early 2026
Threat actors used a modular command-and-control framework from Cavern Manticore to target Israeli government and IT organizations.
Click on any entity below to view its context and source!
source_region
Iran, Islamic Republic of
Introduction
Since early 2026, Check Point Research (CPR) has tracked a
new modular command-and-control framework
used by
Cavern Manticore
, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors.
A new cyber threat group linked to the Iranian government has been targeting Israeli government and IT organizations since early 2026, according to Check Point Research.
industry
Government
Introduction
Since early 2026, Check Point Research (CPR) has tracked a
new modular command-and-control framework
used by
Cavern Manticore
, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors.
A new cyber threat group linked to the Iranian government has been targeting Israeli government and IT organizations since early 2026, according to Check Point Research.
attribution
Check Point Research
Introduction
Since early 2026, Check Point Research (CPR) has tracked a
new modular command-and-control framework
used by
Cavern Manticore
, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors.
A new cyber threat group linked to the Iranian government has been targeting Israeli government and IT organizations since early 2026, according to Check Point Research.
source_region
Israel
Introduction
Since early 2026, Check Point Research (CPR) has tracked a
new modular command-and-control framework
used by
Cavern Manticore
, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors.
A new cyber threat group linked to the Iranian government has been targeting Israeli government and IT organizations since early 2026, according to Check Point Research.
attribution
APT
Introduction
Since early 2026, Check Point Research (CPR) has tracked a
new modular command-and-control framework
used by
Cavern Manticore
, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
The Cavern Agent
3.1 UxTheme Facade and Side-Load Trigger
The
Cavern Agent
is compiled as a
64-bit Mixed-Mode C++/CLI DLL
named
uxtheme.dll
and exports 83 functions that mimic the legitimate Windows theming library.
Every
HTTP-based verb
sends a
fixed Microsoft Edge
User-Agent
(
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 Edg/146.0.0.0
), and the two
C2-bound verbs
(
get
and
send
) additionally attach a custom
X-User-token
header whose value is the
agent ID
with the literal suffix
00
appended.
It resolves its
security-sensitive
Windows APIs at
runtime
through
P/Invoke
descriptor tables, which keep them
out of the PE import
table.
Metrics
infrastructure
3.2
Software Version
3.2 C2 Polling Loop
Upon invocation,
EnableThemeDialogTexture
creates a singleton mutex (
MYMUTEX123HELLP02
or
MYMUTEX123HELLP04
, depending on the build), initializes the local configuration from
config.txt
, and enters an infinite polling loop.
Metrics
infrastructure
3.5
Software Version
3.5 Module Versioning and Self-Update
Cavern implements a
numbered DLL versioning scheme
.
Metrics
infrastructure
3.6
Software Version
3.6 Agent Self-Commands
The agent handles
six built-in self-commands
before reaching the module dispatcher:
Command
Action
001
Update polling interval
002
GZip+Base64 module update (including self-update of
uxtheme.dll
)
003
Toggle debug logging
004
Activate WebSocket communication mode
005
Close WebSocket connection
006
Reconnect WebSocket
3.7 Startup Cleanup as Anti-Forensics
Newer agent builds perform aggressive directory cleanup on first startup: they enumerate all files and subdirectories in the working directory and
delete everything except
the
Communication Module
(
n-HTCommp.dll
), the
configuration file
(
config.txt
), and
log
files.
Metrics
infrastructure
3.7
Software Version
3.6 Agent Self-Commands
The agent handles
six built-in self-commands
before reaching the module dispatcher:
Command
Action
001
Update polling interval
002
GZip+Base64 module update (including self-update of
uxtheme.dll
)
003
Toggle debug logging
004
Activate WebSocket communication mode
005
Close WebSocket connection
006
Reconnect WebSocket
3.7 Startup Cleanup as Anti-Forensics
Newer agent builds perform aggressive directory cleanup on first startup: they enumerate all files and subdirectories in the working directory and
delete everything except
the
Communication Module
(
n-HTCommp.dll
), the
configuration file
(
config.txt
), and
log
files.
Metrics
infrastructure
2
Gzip+Base64
3.6 Agent Self-Commands
The agent handles
six built-in self-commands
before reaching the module dispatcher:
Command
Action
001
Update polling interval
002
GZip+Base64 module update (including self-update of
uxtheme.dll
)
003
Toggle debug logging
004
Activate WebSocket communication mode
005
Close WebSocket connection
006
Reconnect WebSocket
3.7 Startup Cleanup as Anti-Forensics
Newer agent builds perform aggressive directory cleanup on first startup: they enumerate all files and subdirectories in the working directory and
delete everything except
the
Communication Module
(
n-HTCommp.dll
), the
configuration file
(
config.txt
), and
log
files.
Metrics
infrastructure
3.8
Software Version
3.8 Variant Evolution
Three agent builds were recovered, showing
clear iterative
development:
Attribute
Oldest Build
Build
02
Build
04
Mutex
MYMUTEX123HELLP
MYMUTEX123HELLP02
MYMUTEX123HELLP04
C2 Domain
auth.hospitalinstallation.com
google.com.hospitalinstallation.com
google.com.hospitalinstallation.com
Config Storage
id.txt
(plain 7-char ID)
config.txt
(JSON)
config.txt
(JSON)
Self-Commands
001-003
001-006
(adds WebSocket)
001-006
Cleanup
None
Working-dir wipe
Working-dir wipe
Debug Default
true
false
true
4.
Metrics
infrastructure
5.5
Software Version
The Communication Module – “n-HTCommp.dll”
The communication module is compiled as a
NativeAOT
.NET 8 DLL (~
5.5 MB
, with about
21k stripped
framework functions) and exposes a single operational export,
get_version
.
Metrics
data_breach
6
Mb
The Communication Module – “n-HTCommp.dll”
The communication module is compiled as a
NativeAOT
.NET 8 DLL (~
5.5 MB
, with about
21k stripped
framework functions) and exposes a single operational export,
get_version
.
Metrics
infrastructure
5.0
Software Version
Every
HTTP-based verb
sends a
fixed Microsoft Edge
User-Agent
(
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 Edg/146.0.0.0
), and the two
C2-bound verbs
(
get
and
send
) additionally attach a custom
X-User-token
header whose value is the
agent ID
with the literal suffix
00
appended.
Metrics
infrastructure
10.0
Software Version
Every
HTTP-based verb
sends a
fixed Microsoft Edge
User-Agent
(
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 Edg/146.0.0.0
), and the two
C2-bound verbs
(
get
and
send
) additionally attach a custom
X-User-token
header whose value is the
agent ID
with the literal suffix
00
appended.
Metrics
infrastructure
537.36
Software Version
Every
HTTP-based verb
sends a
fixed Microsoft Edge
User-Agent
(
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 Edg/146.0.0.0
), and the two
C2-bound verbs
(
get
and
send
) additionally attach a custom
X-User-token
header whose value is the
agent ID
with the literal suffix
00
appended.
Metrics
infrastructure
146.0.0
Software Version
Every
HTTP-based verb
sends a
fixed Microsoft Edge
User-Agent
(
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 Edg/146.0.0.0
), and the two
C2-bound verbs
(
get
and
send
) additionally attach a custom
X-User-token
header whose value is the
agent ID
with the literal suffix
00
appended.
Metrics
data_breach
312
File_Folder_List
= 311, // 0x137 - create folder (mhm.dll)
FILE_FOLDER_LIST = 312, // 0x138 - list files / folders (mhm.dll)
SEARCH_FILE = 313, // 0x139 - search files (mhm.dll)
MOVE = 314, // 0x13A - move (mhm.dll)
LDAP_TEST = 401, // 0x191 - LDAP bind test (ode.dll)
LDAP_ALL_GROUPS = 402, // 0x192 - enumerate all groups (ode.dll)
LDAP_ALL_USERS = 403, // 0x193 - enumerate all users (ode.dll)
Metrics
data_breach
313
Search_File
= 311, // 0x137 - create folder (mhm.dll)
FILE_FOLDER_LIST = 312, // 0x138 - list files / folders (mhm.dll)
SEARCH_FILE = 313, // 0x139 - search files (mhm.dll)
MOVE = 314, // 0x13A - move (mhm.dll)
LDAP_TEST = 401, // 0x191 - LDAP bind test (ode.dll)
LDAP_ALL_GROUPS = 402, // 0x192 - enumerate all groups (ode.dll)
LDAP_ALL_USERS = 403, // 0x193 - enumerate all users (ode.dll)
Metrics
data_breach
314
Search_File
= 311, // 0x137 - create folder (mhm.dll)
FILE_FOLDER_LIST = 312, // 0x138 - list files / folders (mhm.dll)
SEARCH_FILE = 313, // 0x139 - search files (mhm.dll)
MOVE = 314, // 0x13A - move (mhm.dll)
LDAP_TEST = 401, // 0x191 - LDAP bind test (ode.dll)
LDAP_ALL_GROUPS = 402, // 0x192 - enumerate all groups (ode.dll)
LDAP_ALL_USERS = 403, // 0x193 - enumerate all users (ode.dll)
Metrics
data_breach
402
Search_File
= 311, // 0x137 - create folder (mhm.dll)
FILE_FOLDER_LIST = 312, // 0x138 - list files / folders (mhm.dll)
SEARCH_FILE = 313, // 0x139 - search files (mhm.dll)
MOVE = 314, // 0x13A - move (mhm.dll)
LDAP_TEST = 401, // 0x191 - LDAP bind test (ode.dll)
LDAP_ALL_GROUPS = 402, // 0x192 - enumerate all groups (ode.dll)
LDAP_ALL_USERS = 403, // 0x193 - enumerate all users (ode.dll)
Metrics
data_breach
21
Byte
[]
and
PageName = "cac.aspx"
constants the agent carries,
POSTs
s=<timestamp>&id=<AgentID>&q=<XOR+Base32 telemetry>
to
, and expects a response whose body starts with a fixed
21-byte JPEG magic header
and whose
Content-Disposition: filename=
value is
XOR+Base32-encrypted
with the
AgentID
, then drops the carved payload into the same local
inpt\
directory the agent reads from.
Metrics
data_breach
5
File Manager
5.1 File Manager – “mhm.dll”
The
file manager module
implements the broadest command surface across three of the
enum
blocks (the
1xx
information
block
101-104
, the
3xx
file
/
directory
block
301-314
, and the
8xx
archive
block
801-806
): host information collection, DPAPI decryption, drive/file/directory enumeration, recursive file search with content matching, GZip+Base64 file transfer in both directions, ZIP archive creation/extraction, and file/directory manipulation.
Metrics
financial
314
Directory Block
5.1 File Manager – “mhm.dll”
The
file manager module
implements the broadest command surface across three of the
enum
blocks (the
1xx
information
block
101-104
, the
3xx
file
/
directory
block
301-314
, and the
8xx
archive
block
801-806
): host information collection, DPAPI decryption, drive/file/directory enumeration, recursive file search with content matching, GZip+Base64 file transfer in both directions, ZIP archive creation/extraction, and file/directory manipulation.
Metrics
data_breach
5
Sql Database Browser
5.2 SQL Database Browser – “db.dll”
The
database module
implements a REST-like route dispatcher that accepts
JSON commands
with operator-supplied
SQL Server credentials
passed through
pseudo-HTTP
headers.
Metrics
infrastructure
3
Custom Appdomain Isolation
3.3 Custom AppDomain Isolation with Post-Execution Unload
One of the most technically interesting mechanisms in the Cavern Agent is its module hosting strategy.
Metrics
data_breach
3
Mb Binary
The result is usually a 3-6 MB binary with
thousands of stripped
framework functions, a
.managed
executable section, and a
hydrated
BSS-like section where string objects are materialized only at runtime.
Metrics
financial
1
Tool
Any automated analysis tool that invokes ordinal
#1
, or any other default export, will observe only inert DLL loading behavior and conclude the sample is benign.
Metrics
financial
20
Export Ordinal
The real backdoor personality sits entirely behind export ordinal
#20
(
0x14
).
Metrics
financial
601
Cav3Rn
= 502, // 0x1F6 - list processes (not in modular set; older Cav3rn)
REG_ADD = 601, // 0x259 - registry add (not in modular set; older Cav3rn)
REG_DEL
Metrics
financial
702
Srv_Reset
= 602, // 0x25A - registry delete (not in modular set; older Cav3rn)
REG_QRY_SUBKEYS = 603, // 0x25B - registry query subkeys (not in modular set; older Cav3rn)
REG_QRY_VALUE = 604, // 0x25C - registry query value (not in modular set; older Cav3rn)
SRV_LIST = 701, // 0x2BD - list services (not in modular set; older Cav3rn)
SRV_RESET = 702, // 0x2BE - reset service (not in modular set; older Cav3rn)
SRV_START = 703, // 0x2BF - start service (not in modular set; older Cav3rn)
SRV_STOP = 704, // 0x2C0 - stop service (not in modular set; older Cav3rn)
GZ_READ = 801, // 0x321 - GZip read (download)
Metrics
infrastructure
21
Loaded Api Descriptors
Static analysis of the P/Invoke resolution data recovered
21 dynamically-loaded
API descriptors.
Intelligence Sources
Infosecurity-Magazine
2026-07-06
New Iran-Nexus Hacking Group Targets Israel Government and IT Sectors
Infosecurity-Magazine
Zero Day Fans
2026-07-06
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-26T07:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
72x
organisation
Identified Entity
Cavern Manticore
entity
10x
infrastructure
Software Version
3.2
version
5x
attribution
Attributing Entity
Check Point Research
authority
5x
general metric
=
306
=
4x
timeline
Temporal Reference
early 2026
date
4x
target region
Target Country
United States
country
4x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
3x
tactic
Cyber Operation Type
Reconnaissance
tactic
3x
general metric
Mhm.Dll
102
mhm.dll
3x
data breach
Search_File
313
search_file
3x
general metric
Ode.Dll
406
ode.dll
2x
source region
Origin Country
Iran, Islamic Republic of
country
2x
industry
Targeted Sector
Government
sector
2x
threat actor
APT Group
OilRig
actor
2x
general metric
Startup Cleanup
5
startup cleanup
Contextual Telemetry
Context Block
51 METRICS
campaign
Campaign
Operation Epic Fury
operation
general metric
Ldap
5
ldap
general metric
Network Reconnaissance Module
5
network reconnaissance module
general metric
.Net
8
.net
infrastructure
Affected Product
Windows
software
general metric
Uxtheme Facade
3
uxtheme facade
general metric
Bit
64
bit
general metric
Functions
83
functions
general metric
C2 Polling Loop
3
c2 polling loop
general metric
Module Versioning
4
module versioning
general metric
Self Command
2
self command
general metric
Agent Self Commands
4
agent self commands
general metric
Command Action
1
command action
infrastructure
Gzip+Base64
2
gzip+base64
general metric
Toggle
3
toggle
general metric
Websocket Communication Mode
4
websocket communication mode
general metric
Reconnect Websocket
6
reconnect websocket
general metric
Agent Builds
4
agent builds
general metric
Plain Char Id
7
plain char id
data breach
Mb
6
mb
general metric
Type
0
type
general metric
Info
101
info
general metric
Sql_Query
201
sql_query
general metric
Move Folder
309
move folder
data breach
File_Folder_List
312
file_folder_list
general metric
Entities
405
entities
general metric
Gz_Write
802
gz_write
general metric
Dbbrowser
901
dbbrowser
general metric
Command Ids
61
command ids
data breach
Byte
21
byte
data breach
File Manager
5
file manager
financial
Directory Block
314
directory block
general metric
8Xx Archive Block
801
8xx archive block
general metric
Block
806
block
data breach
Sql Database Browser
5
sql database browser
general metric
Websocket Tunnel
6
websocket tunnel
infrastructure
Custom Appdomain Isolation
3
custom appdomain isolation
data breach
Mb Binary
3
mb binary
general metric
%
60
%
general metric
Exports
82
exports
financial
Tool
1
tool
financial
Export Ordinal
20
export ordinal
general metric
Module Dispatch
3
module dispatch
general metric
Section
2
section
financial
Cav3Rn
601
cav3rn
general metric
Older Reg_Qry_Value
604
older reg_qry_value
general metric
Older Srv_List
701
older srv_list
financial
Srv_Reset
702
srv_reset
general metric
Older Srv_Start
703
older srv_start
general metric
Cav3Rn
704
cav3rn
infrastructure
Loaded Api Descriptors
21
loaded api descriptors
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.