Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors cavern manticore

Also known as: tracked as, Hyadina, Model Diplomat Jul 7, 2026, Ferocious Kitten, n8n, N-cent, Smoke Sandstorm, UNC1549, Mint Sandstorm, MuddyWater, LowEraser, TA456, Tortoiseshell, Yellow Liderc, Agrius, BlackShadow, Newscaster, Parastoo, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, APT35, Imperial Kitten, Cav3rn, Charming Kitten, Mango Sandstorm, watering hole attacks

Description

Cavern Manticore combines several sophisticated tactics that blur the lines between traditional ransomware operations and complex nation‑state intrusion campaigns. At its core lies a modular .NET C2 framework, Cavern C2, that is compiled in multiple formats—standard .NET Framework, Mixed‑Mode C++/CLI, and Static AOT—to thwart static analysis and sandbox detection. The framework contains a core agent and a collection of specialist post‑exploitation modules for file and database manipulation, LDAP queries, network reconnaissance, tunneling, and more. The actor’s initial access vectors are primarily through abuse of legitimate RMM software such as SysAid, leveraging the privileged nature of these tools and their widespread deployment across target environments. Once inside, they hijack AppDomainManager to facilitate lateral movement and can also pivot via compromised software update mechanisms. To exfiltrate data, Cavern Manticore frequently uses commercial cloud storage or remote printing capabilities when clipboard restrictions are in place. Targeting extends beyond IT systems. The group has repeatedly exploited PLCs and SCADA devices—particularly Rockwell Automation/Allen‑Bradley controllers—in critical infrastructure environments, raising concerns for the broader industrial sector. Their use of a web‑shell style ASP.NET handler (cac.aspx) running on attacker–controlled IIS servers provides a resilient and stealthy C2 channel that can survive network filtering. Cavern Manticore’s operations exhibit clear indicators of supply‑chain compromise, stepping‐stone access via IT providers, and advanced obfuscation techniques such as XOR masking combined with Base64 encoding. The actor remains largely active and capable of evolving its attack surface while maintaining strong defensive evasion through multi‑compiled binaries.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Education
Energy
Media
Non profit
Telecommunications
Transportation
Information technology
Healthcare
Aviation
Nuclear

Targeted Countries / Regions

Israel
IR
IL
US
AE
EG
UA
CN
SA
IQ
DE
CA

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 22 hours ago

Executive Summary

Cavern Manticore is an Iran‐linked threat actor that primarily targets Israeli government and IT sectors using a modular .NET C2 framework called Cavern C2. The group leverages compromised Remote Monitoring & Management (RMM) tools, supply‑chain footholds through trusted service providers, and web‑based ASP.NET shells to gain initial access, move laterally, and exfiltrate data to commercial cloud services.

Goals & Targeting

The strategic objective of Cavern Manticore appears to be long‑term espionage and intellectual property theft, focusing on high‑value Israeli institutions spanning government, defense contractors, and critical infrastructure operators. By establishing footholds through compromised RMM tools and supply‑chain channels, the group can persistently penetrate networks, expand lateral coverage, and surveil sensitive systems over extended periods. The selection of SCADA/PLC targets suggests an intent to gather operational data or potentially sabotage industrial processes, further aligning with national strategic goals. Targeted sectors include not only governmental and defense entities but also finance, energy, telecommunications, education, healthcare, media, non‑profit, information technology, aviation, and nuclear facilities, reflecting a broad threat appetite for any institution with valuable operational data or critical services. The geographic focus is primarily Israel, supplemented by other Middle Eastern and Western nations where the attacker’s infrastructure may operate. Overall, Cavern Manticore pursues strategic espionage objectives using stealth, supply‑chain exploitation, and targeted industrial attacks to gain sustainable access and leverage adversarial data for political or economic advantage.

Enhanced Description

Key Capabilities

  • Deploying a modular .NET C2 framework (Cavern C2) compiled in multiple formats
  • Releasing RAT variants such as NightLedger
  • Leveraging compromised RMM tools for initial access and lateral movement
  • Hijacking AppDomainManager to facilitate lateral pivoting
  • Exploiting PLCs/SCADA devices, particularly Rockwell Automation/Allen‑Bradley controllers
  • Transferring exfiltrated data to commercial cloud storage and remote printing services
  • Browser‐based remote desktop through RMM solutions
  • Deploying a webshell‑style ASP.NET handler (cac.aspx) for CoT communication
  • XOR‑based obfuscation combined with Base64 encoding
  • Misusing compromised software update mechanisms to expand footholds

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.sentinelone.com — Cited by web research for: Ferocious Kitten
  2. thehackernews.com — Cited by web research for: n8n
  3. thehackernews.com — Cited by web research for: Smoke Sandstorm
  4. research.checkpoint.com — Cited by web research for: Payload
  5. research.checkpoint.com — Cited by web research for: Rogue
  6. www.hivepro.com — Cited by web research for: Hive

Intel Summary

9

Techniques

48

Tools

0

Campaigns

45

IOCs

0

Observed Data

6

Tactics

Tags

Critical Infrastructure
Backdoor / C2
Government Targeting

Details

MITRE ID
APT35
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
I
Confidence
55%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.