# Cavern Manticore

> As of 2026-08-17, Cavern Manticore is a Iran-nexus threat actor tracked by Threadlinqs Intelligence across 7 threats spanning malware, apt. ATT&CK coverage spans 131 techniques across 13 tactics in 7 of 7 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel), T1071.001 (Web Protocols).

- **Nation:** Iran
- **Tracked threats:** 7
- **Categories:** MALWARE, APT
- **As of:** 2026-08-17

## ATT&CK techniques observed

131 techniques observed across 7 of 7 tracked threats. Tactics: Command and Control (24), Discovery (22), Stealth (formerly Defense Evasion) (15), Collection (13), Lateral Movement (12), Credential Access (9).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 7 of 7 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 6 of 7 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 6 of 7 tracked threats
- [T1135](https://intel.threadlinqs.com/technique/T1135) Network Share Discovery — Discovery — observed in 6 of 7 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 6 of 7 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 5 of 7 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 5 of 7 tracked threats
- [T1071.004](https://intel.threadlinqs.com/technique/T1071.004) Application Layer Protocol: DNS — Command and Control — observed in 5 of 7 tracked threats
- [T1199](https://intel.threadlinqs.com/technique/T1199) Trusted Relationship — Initial Access — observed in 5 of 7 tracked threats
- [T1574.001](https://intel.threadlinqs.com/technique/T1574.001) DLL — Stealth (formerly Defense Evasion) — observed in 5 of 7 tracked threats
- [T1008](https://intel.threadlinqs.com/technique/T1008) Fallback Channels — Command and Control — observed in 4 of 7 tracked threats
- [T1018](https://intel.threadlinqs.com/technique/T1018) Remote System Discovery — Discovery — observed in 4 of 7 tracked threats
- [T1020](https://intel.threadlinqs.com/technique/T1020) Automated Exfiltration — Exfiltration — observed in 4 of 7 tracked threats
- [T1021.002](https://intel.threadlinqs.com/technique/T1021.002) SMB/Windows Admin Shares — Lateral Movement — observed in 4 of 7 tracked threats
- [T1087.002](https://intel.threadlinqs.com/technique/T1087.002) Account Discovery: Domain Account — Discovery — observed in 4 of 7 tracked threats

## Tracked threats

- [Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based Channel Selection and Google Apps Script Relay](https://intel.threadlinqs.com/threat/TL-2026-2053) — HIGH
- [HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern Manticore / Iran MOIS-Nexus)](https://intel.threadlinqs.com/threat/TL-2026-1601) — HIGH
- [Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar (Microsoft Graph API) and DNS AAAA Records for C2 and Credential Recovery](https://intel.threadlinqs.com/threat/TL-2026-1588) — HIGH
- [HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware Targeting Israeli Organizations (Cavern Manticore)](https://intel.threadlinqs.com/threat/TL-2026-1567) — HIGH
- [HollowGraph Malware Abuses Microsoft Graph API and M365 Calendar Events (Future-Dated 2050) for Stealthy Command-and-Control](https://intel.threadlinqs.com/threat/TL-2026-1561) — HIGH
- [HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to Cavern Manticore/Lyceum (Low Confidence)](https://intel.threadlinqs.com/threat/TL-2026-1553) — HIGH
- [Cavern Manticore: Iran-Linked Modular .NET C2 Framework Targeting Israeli Government and IT Sectors via SysAid RMM Abuse](https://intel.threadlinqs.com/threat/TL-2026-1137) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Cavern%20Manticore
