Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
Check Point reports that the Iran-linked threat cluster “Cavern Manticore” is using a previously undocumented modular command-and-control framework called Cavern (aka Cav3rn) to target Israeli organizations, with IT service providers and government entities among the main focuses. The activity leverages SysAid software update functionality to trigger DLL side-loading and then delivers additional payload modules via the Cavern agent, enabling tailored reconnaissance, data theft, and lateral movement while complicating analysis through mixed compilation formats. Separately, CVE-2025-52691, CVE-2025-68613, CVE-2025-9316, CVE-2025-34291, and CVE-2025-54068 are referenced as part of broader exploitation activity tied to the same state-linked operations.