Cavern, also referred to as Cav3rn, is a modular .NET-based post-exploitation command-and-control framework associated with the Iran-nexus threat cluster tracked as Cavern Manticore and linked by reporting to MOIS-aligned activity. It has been used primarily in espionage operations targeting Israeli organizations, especially government entities and IT service providers, and has shown technical overlaps with MuddyWater and Lyceum tradecraft.
The framework is designed as a plugin-based toolkit in which a core agent retrieves and orchestrates additional modules according to operator needs. Documented modules support command-and-control communications, file operations and data theft, SQL database interaction, Active Directory and LDAP reconnaissance, network discovery, port scanning, SMB credential attacks, and SOCKS5 or WebSocket tunneling. The framework uses multiple .NET compilation formats, including .NET Framework, mixed-mode C++/CLI, and NativeAOT, as an anti-analysis measure. Additional defensive-evasion features include AppDomain isolation for managed modules, startup cleanup, export spoofing, and other implementation choices intended to reduce forensic visibility and complicate reverse engineering.
Observed intrusion chains show Cavern being deployed after abuse of SysAid software update functionality to trigger DLL sideloading through a legitimate application, resulting in execution of the Cavern agent. Operators have also used compromised remote monitoring and management tooling and trusted service-provider relationships to move laterally and reach downstream targets. Once established, Cavern functions as a flexible post-compromise platform for reconnaissance, credential-focused activity, data collection, tunneling, and broader hands-on-keyboard operations.
A related Windows implant, HollowGraph, has been linked with high confidence as a variant or component within the Cavern framework. HollowGraph uses compromised Microsoft 365 mailboxes and the Microsoft Graph API as a covert bidirectional command-and-control and exfiltration channel, with a secondary DNS-based credential refresh mechanism. This demonstrates Cavern’s modular evolution toward stealthier cloud-backed communications while retaining its broader espionage-oriented architecture.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Group-IB relie HollowGraph au framework Cavern, que Check Point associe à un opérateur à nexus iranien suivi sous le nom Cavern Manticore.
Researchers analysing the module believe it is part of the Cavern command-and-control framework that has been previously linked to an Iranian threat actor targeting entities in Israel.
Group-IB ties HollowGraph to Cavern with high confidence, on shared command syntax and matching internal tasking. Cavern is a modular backdoor framework that Check Point documented earlier this month...
Group-IB ties HollowGraph to Cavern with high confidence, on shared command syntax and matching internal tasking. Cavern is a modular backdoor framework that Check Point documented earlier this month...
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Trois formats de compilation forçant l’analyste à utiliser plusieurs toolchains simultanément ... NativeAOT : résolution des API sensibles via tables de descripteurs P/Invoke
To remain under the radar, the threat actor creates calendar events dated May 13, 2050, with the title in specific formats. Commands and exfiltrated data are concealed within files attached to these calendar entries.
The configuration file is stored as logAzure.txt to appear as a regular log file.
The malware uses hardcoded credentials to authenticate to the Microsoft Graph API via a compromised Microsoft 365 account.
Module LDAP ode.dll Reconnaissance AD, brute-force LDAP ... Module réseau n-ten.dll ... brute-force SMB
A newly identified Windows malware sample abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command and control (C2) channel. | The malware supports two commands, get and send, and relies entirely on trusted third-party infrastructure for communication, never reaching out directly to attacker-owned servers for payload delivery.
the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks like ordinary Microsoft 365 chatter
HollowGraph also uses DNS tunneling to deliver and refresh Microsoft Entra ID (Azure AD) credentials needed to authenticate to the Graph channel.
A newly identified Windows malware sample abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command and control (C2) channel.
Researchers note that the mailbox calendars are used as a “dead drop” to store the data; hence, HollowGraph does not use traditional C2 servers to avoid detection.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A larger malware/toolkit framework that HollowGraph is believed to be a variant or component of, based on command format and structure.
A malware framework assessed to be linked to HOLLOWGRAPH.
Offensive framework linked in the reporting to HollowGraph and associated by prior research with the Cavern Manticore operator.
A command-and-control framework that HollowGraph is believed to be part of.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.