OSINTxLab
OSINT://LAB INTEL NODE ONLINE 2026.07.28 20:13 CST
文章详情

正文阅读

分类:威胁情报

2026-07-08 1 分钟 17 阅读

Iran-Linked Hackers Targets Israeli Organizations

OSINTxLab 17 阅读 · 1 分钟
事件类型
Cyber Attack
报告时间
2026-07-07 03:20:49
被攻击国家/地区
Israel
被攻击行业
[]
被攻击组织
[]
被攻击域名
[]
攻击组织
None
信息来源
openweb
Original Text
原文内容
查看原文

Iran-linked hackers associated with MOIS hackers are using a new modular C2 framework called Cavern (Cav3rn) against Israeli IT and government targets. The group tracked as Cavern Manticore, overlaps with MuddyWater and related Iranian APTs. Cavern is a .NET-based malware framework designed for stealth, using multiple compilation methods to make analysis difficult. It separates core communication from modules used for file access, network scanning, and system reconnaissance. Attacks begin by compromising IT tools like SysAid, then using DLL side-loading to deploy the malware and connect to a C2 server for additional payloads. The operation relies on supply-chain abuse and trusted IT providers to move laterally and exfiltrate data.