Cavern Manticore is an Iran-nexus APT targeting Israeli government and IT sectors with a modular .NET C2 framework.
Analyst brief
Cavern Manticore is an Iran-nexus APT, likely linked to the MOIS, primarily targeting Israeli government and IT sectors. The group employs a modular command-and-control framework built on a shared .NET foundation, using multiple compilation formats to create an anti-analysis layer that hinders detection. Demonstrating high operational tempo and disciplined target selection, particularly in campaigns like 'Operation Epic Fury,' they decouple core infrastructure from mission-specific modules to enhance agility. Defenders should focus on anomalous .NET assembly loads, modular C2 traffic patterns, and anti-analysis techniques directed at government and IT environments.
Cavern Manticore
unknown
Cavern Manticore is an Iran-nexus APT primarily targeting Israeli organizations in the government and IT sectors, linked to the MOIS. The group employs a modular command-and-control framework built on a shared .NET foundation, utilizing multiple compilation formats to create an anti-analysis layer. Their operations demonstrate a high operational tempo and a disciplined approach to target selection, particularly during campaigns like "Operation Epic Fury." By decoupling core infrastructure from mission-specific modules, Cavern Manticore enhances operational agility while complicating detection efforts for defenders.