Activity timeline
Cavern Manticore appears in 7 tracked threats between and ; the busiest month was 2026-07 with 6 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 7 of 7 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 6 of 7 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 6 of 7 tracked threats
- T1135 Network Share Discovery — Discoveryobserved in 6 of 7 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 6 of 7 tracked threats
- T1005 Data from Local System — Collectionobserved in 5 of 7 tracked threats
- T1046 Network Service Discovery — Discoveryobserved in 5 of 7 tracked threats
- T1071.004 Application Layer Protocol: DNS — Command and Controlobserved in 5 of 7 tracked threats
- T1199 Trusted Relationship — Initial Accessobserved in 5 of 7 tracked threats
- T1574.001 DLL — Stealth (formerly Defense Evasion)observed in 5 of 7 tracked threats
- T1008 Fallback Channels — Command and Controlobserved in 4 of 7 tracked threats
- T1018 Remote System Discovery — Discoveryobserved in 4 of 7 tracked threats
- T1020 Automated Exfiltration — Exfiltrationobserved in 4 of 7 tracked threats
- T1021.002 SMB/Windows Admin Shares — Lateral Movementobserved in 4 of 7 tracked threats
- T1087.002 Account Discovery: Domain Account — Discoveryobserved in 4 of 7 tracked threats
Tracked threats
- Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based Channel Selection and Google Apps Script RelayHIGH
- HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern Manticore / Iran MOIS-Nexus)HIGH
- Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar (Microsoft Graph API) and DNS AAAA Records for C2 and Credential RecoveryHIGH
- HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware Targeting Israeli Organizations (Cavern Manticore)HIGH
- HollowGraph Malware Abuses Microsoft Graph API and M365 Calendar Events (Future-Dated 2050) for Stealthy Command-and-ControlHIGH
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to Cavern Manticore/Lyceum (Low Confidence)HIGH
- Cavern Manticore: Iran-Linked Modular .NET C2 Framework Targeting Israeli Government and IT Sectors via SysAid RMM AbuseHIGH