Also known as: tracked as, Hyadina, Model Diplomat Jul 7, 2026, Ferocious Kitten, n8n, N-cent, Smoke Sandstorm, UNC1549, Mint Sandstorm, MuddyWater, LowEraser, TA456, Tortoiseshell, Yellow Liderc, Agrius, BlackShadow, Newscaster, Parastoo, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, APT35, Imperial Kitten, Cav3rn, Charming Kitten, Mango Sandstorm, watering hole attacks
Cavern Manticore combines several sophisticated tactics that blur the lines between traditional ransomware operations and complex nation‑state intrusion campaigns. At its core lies a modular .NET C2 framework, Cavern C2, that is compiled in multiple formats—standard .NET Framework, Mixed‑Mode C++/CLI, and Static AOT—to thwart static analysis and sandbox detection. The framework contains a core agent and a collection of specialist post‑exploitation modules for file and database manipulation, LDAP queries, network reconnaissance, tunneling, and more. The actor’s initial access vectors are primarily through abuse of legitimate RMM software such as SysAid, leveraging the privileged nature of these tools and their widespread deployment across target environments. Once inside, they hijack AppDomainManager to facilitate lateral movement and can also pivot via compromised software update mechanisms. To exfiltrate data, Cavern Manticore frequently uses commercial cloud storage or remote printing capabilities when clipboard restrictions are in place. Targeting extends beyond IT systems. The group has repeatedly exploited PLCs and SCADA devices—particularly Rockwell Automation/Allen‑Bradley controllers—in critical infrastructure environments, raising concerns for the broader industrial sector. Their use of a web‑shell style ASP.NET handler (cac.aspx) running on attacker–controlled IIS servers provides a resilient and stealthy C2 channel that can survive network filtering. Cavern Manticore’s operations exhibit clear indicators of supply‑chain compromise, stepping‐stone access via IT providers, and advanced obfuscation techniques such as XOR masking combined with Base64 encoding. The actor remains largely active and capable of evolving its attack surface while maintaining strong defensive evasion through multi‑compiled binaries.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Cavern Manticore is an Iran‐linked threat actor that primarily targets Israeli government and IT sectors using a modular .NET C2 framework called Cavern C2. The group leverages compromised Remote Monitoring & Management (RMM) tools, supply‑chain footholds through trusted service providers, and web‑based ASP.NET shells to gain initial access, move laterally, and exfiltrate data to commercial cloud services.
Goals & Targeting
The strategic objective of Cavern Manticore appears to be long‑term espionage and intellectual property theft, focusing on high‑value Israeli institutions spanning government, defense contractors, and critical infrastructure operators. By establishing footholds through compromised RMM tools and supply‑chain channels, the group can persistently penetrate networks, expand lateral coverage, and surveil sensitive systems over extended periods. The selection of SCADA/PLC targets suggests an intent to gather operational data or potentially sabotage industrial processes, further aligning with national strategic goals. Targeted sectors include not only governmental and defense entities but also finance, energy, telecommunications, education, healthcare, media, non‑profit, information technology, aviation, and nuclear facilities, reflecting a broad threat appetite for any institution with valuable operational data or critical services. The geographic focus is primarily Israel, supplemented by other Middle Eastern and Western nations where the attacker’s infrastructure may operate. Overall, Cavern Manticore pursues strategic espionage objectives using stealth, supply‑chain exploitation, and targeted industrial attacks to gain sustainable access and leverage adversarial data for political or economic advantage.
Enhanced Description
Key Capabilities
No campaigns linked yet.
No observed data linked yet.
9
Techniques
48
Tools
0
Campaigns
45
IOCs
0
Observed Data
6
Tactics