- What: Iranian hackers are using a new modular C2 framework called Cavern against Israeli organizations.
- Impact: Targeted IT providers and government sectors may be at risk of cyber espionage.
Threat Intelligence Iranian hackers use new modular C2 framework against Israeli organizations July 6, 2026 Share By SC Staff As reported by The Hacker News, an Iranian hacking group, linked to the country's Ministry of Intelligence and Security, has been observed deploying a novel modular command-and-control (C2) framework named Cavern against Israeli organizations. This framework, also known as Cav3rn, has been used in attacks primarily targeting IT providers and government sectors. The threat cluster, dubbed Cavern Manticore by Check Point Research, exhibits tactical similarities with known groups like MuddyWater and Lyceum. The Cavern framework is built on a .NET foundation and utilizes multiple compilation formats, including .NET Framework, .NET Mixed-Mode C++/CLI, and .NET Native AOT, serving as an anti-analysis layer. The framework consists of a Cavern Agent and various Cavern modules, allowing for tailored deployments for reconnaissance, data theft, tunneling, and lateral movement. The attack chain often begins by exploiting SysAid's software update feature to execute a trojanized DLL containing the Cavern Agent. This agent then contacts a C2 server to download additional post-exploitation modules. These modules include capabilities for file operations, database manipulation, Active Directory reconnaissance, network scanning, and tunneling. The attackers have been observed moving from an initial IT provider to a second-hop provider, leveraging trusted relationships within the software supply chain. They also appear to use browser-based remote desktop technologies and features like remote printing for data exfiltration. Source: The Hacker News SC Staff Related Threat Intelligence 7 arrested in Vietnam for operating large anime piracy site HiAnime SC Staff July 6, 2026 HiAnime, which operated under various domains including Zoro.to and Aniwatch, provided free access to a vast library of anime, attracting hundreds of millions of monthly visitors and briefly surpassing legal streaming platforms in web traffic. Threat Intelligence Major Russian-language cybercrime forum XSS.is shut down, alleged admin arrested SC Staff July 1, 2026 Europol coordinated the operation, dubbed Ratatouille, which dismantled XSS.is, a forum with over 50,000 members. Threat Intelligence US DOJ seizes nearly 400 domains used for illegal World Cup streaming SC Staff July 1, 2026 The US Justice Department's Criminal Division, in coordination with the International Computer Hacking and Intellectual Property (ICHIP) network, took down the domains for violating copyright laws. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms DNS Spoofing Deauthentication Attack Defacement Dictionary Attack Distributed Scans Domain Hijacking DumpSec Google Hacking Password Cracking Reconnaissance You can skip this ad in 5 seconds