Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based Channel Selection and Google Apps Script Relay

Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based (TL-2026-2053), also tracked as Project CAV3RN, is a high-severity malware campaign, first published 2026-08-17. It is attributed to Cavern Manticore (Iran) with medium confidence, affects Microsoft Microsoft 365 / Exchange Online (Graph API calendar), maps to 19 MITRE ATT&CK techniques (T1027, T1071.001, T1071.004), and is covered by 9 detection rules and 28 indicators of compromise.

Key facts for TL-2026-2053

Threat ID
TL-2026-2053
Also known as
Project CAV3RN
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-08-17
Last reviewed
2026-08-17
Attribution
Cavern Manticore
Attribution confidence
MEDIUM
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
government administration, it services msp, nuclear energy, defense
Target regions
israel, united states of america, Middle East
Detection rules
9
Indicators of compromise
28

Malware and tooling in Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based

Malware and tooling: CAV3RN, HOLLOWGRAPH, TAMECAT - S1193, SysAid

Iran-linked cluster Cavern Manticore (aka Cav3rn, MOIS-affiliated, overlapping MuddyWater and OilRig sub-group Lyceum) has evolved its modular CAV3RN C2 framework to query DNS A-records under m.studiotikva[.]com before every transaction, using the response's final octet to route traffic through a Google Apps Script relay or a direct HTTPS endpoint. A companion module, HOLLOWGRAPH, hides C2 tasking and exfiltration inside Microsoft 365 calendar events via the Graph API, and the wider toolset overlaps with the TAMECAT surveillance framework used by Iran-linked APT42/TA453. Targeting spans Israeli government/IT-provider entities and, via APT42's parallel operations, nuclear-energy-sector and government personnel.

How Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based works

Cavern Manticore (previously tracked under the leetspeak name Cav3rn) is an Iran-nexus threat cluster, assessed as MOIS-affiliated, whose CAV3RN command-and-control framework has been under research-community observation since at least December 2025 (Kaspersky) with a major public disclosure by Check Point Research on 6 July 2026. The framework is modular and plugin-based: an Agent component (`uxtheme.dll`, DLL-sideloaded via a trojanized WinDirStat.exe execution path) loads functional modules for file operations (`mhm.dll`), SQL database access (`db.dll`), LDAP/Active Directory reconnaissance including credential brute-force (`ode.dll`), network reconnaissance (`n-ten.dll`), and SOCKS5/WebSocket tunneling (`n-sws.dll`). Modules are compiled in a deliberate mix of pure .NET Framework (IL-only), Mixed-Mode C++/CLI, and .NET 8 NativeAOT builds, a strategy that raises reverse-engineering cost per sample and keeps most binaries at zero or near-zero AV detection on VirusTotal. Initial access in the Check Point-documented campaign involved abuse of a legitimate SysAid RMM software-deployment feature, consistent with multi-hop compromise through a trusted IT-provider relationship before reaching Israeli government and IT-sector victims.

As of the August 2026 disclosure (Kaspersky Securelist, 'Project CAV3RN continues', 11 August 2026), the communications layer has been rearchitected around a new domain, studiotikva[.]com (first registered February 2024, allowed to expire February 2026, then re-registered 12 May 2026 via Dynadot and re-delegated to RouterHosting LLC infrastructure on 19 May 2026). The updated communication module (`GoogleService.dll`, .NET 8 NativeAOT) and an inter-component broker (`rnp.dll`, masquerading as the RNP OpenPGP library) query DNS A-records at `<nonce><error-state>.<hex-client-id>.m.studiotikva[.]com` before each transaction; the fourth octet of the returned address is a compact control signal that selects a direct HTTPS request to `api.studiotikva[.]com/api/v1/update/check`, a POST to a Google Apps Script deployment at `script.google[.]com/macros/s/{deployment-ID}/exec` acting as a relay to the real backend, or transaction termination, depending on the octet value and the module's tracked error state. The malware can validate whether its Apps Script deployment ID is stale by comparing a digest against a DNS response, and pull a replacement ID via small chunked DNS responses, letting operators rotate the Google-fronted relay without redeploying the implant. To ordinary network monitoring this traffic resembles legitimate access to a Google-hosted automation service.

A companion module, HOLLOWGRAPH (.NET NativeAOT DLL, first observed operating 3 June-9 July 2026 and reported by Group-IB), abuses the Microsoft Graph API through a compromised Microsoft 365 mailbox, treating the account's calendar as a two-way dead-drop: operators plant tasking as calendar events dated far in the future (2050-05-13), and the implant reads 'get'/'send' commands and exfiltrates staged files as encrypted calendar attachments, secured with hybrid RSA-OAEP/AES-256-GCM using separate key pairs for inbound and outbound traffic. A secondary DNS-tunneling channel to cloudlanecdn[.]com refreshes Microsoft Entra ID application credentials (tenant ID, client ID, client secret, mailbox) in small AAAA-record chunks, writing results to a local `logAzure.txt`. Group-IB identified at least 12 HOLLOWGRAPH-infected systems (3 actively communicating), all consistent with Israeli targeting, and noted technical overlap with Lyceum at low-to-medium confidence.

The broader toolset referenced alongside Cavern/CAV3RN includes TAMECAT, a modular PowerShell-based surveillance/collection framework associated with Iran-linked APT42 (closely associated with TA453) and analyzed by DarkAtlas. TAMECAT performs host/network discovery, arbitrary command execution, browser credential and cookie theft (targeting Edge/Chrome via the DevTools Protocol), Outlook .ost mailbox collection, and screenshot capture, communicating over HTTPS to Netlify-hosted endpoints with Discord/Telegram as secondary C2 channels. Delivery in the associated 'SpearSpecter' campaign (deployment evidence from late April 2026) uses spear-phishing with podcast/conference pretexts leading to a PDF-themed Windows shortcut (`Document.pdf.lnk`) that triggers a `search-ms:` URI, WebDAV access via `rundll32.exe davclnt.dll,DavSetCookie`, and an obfuscated PowerShell loader chain; an alternate route uses macro-enabled OOXML workbooks that drop registry-persisted (`HKCU\Software\Classes\Key`, RunOnce) PowerShell controllers. DarkAtlas also documents APT42's systematic use of generative AI across the operation lifecycle - target research, persona/pretext generation, multilingual lure translation, and malware coding/debugging - explicitly tying the toolset to defense officials, government personnel, think-tank researchers, and nuclear-energy-sector individuals, including a March 2026 operation against a US think-tank employee during an active US-Iran conflict window.

While Check Point, Group-IB, and DarkAtlas each hedge their attribution (technical overlaps with MuddyWater/Lyceum for Cavern/CAV3RN and HOLLOWGRAPH; APT42/TA453 for TAMECAT) rather than issuing a single unified actor name, the shared Iran-MOIS nexus, overlapping TTPs (DLL sideloading, abuse of trusted cloud services for C2, modular .NET/PowerShell tradecraft), and convergent targeting of Israeli and nuclear-energy/government entities are why they are tracked together as part of the same reporting cluster.

MITRE ATT&CK techniques used in TL-2026-2053

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1218.011 Rundll32

Command and Control

T1071.001 Web Protocols; T1071.004 DNS; T1102.002 Bidirectional Communication; T1572 Protocol Tunneling

Discovery

T1087.002 Domain Account; T1135 Network Share Discovery

Credential Access

T1110 Brute Force; T1555.003 Credentials from Web Browsers

Collection

T1113 Screen Capture; T1114.001 Local Email Collection

Execution

T1204.002 Malicious File

Persistence

T1547.001 Registry Run Keys / Startup Folder

lateral-movement

T1550.001 Application Access Token

Initial Access

T1566.001 Spearphishing Attachment

stealth

T1574.001 DLL

Resource Development

T1583.001 Domains

Affected products and versions in Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based

  • Microsoft — Microsoft 365 / Exchange Online (Graph API calendar)
    Vulnerable versions: Abuse of legitimate Graph API calendar functionality via a compromised mailbox, not a product defect
  • SysAid — SysAid RMM
    Vulnerable versions: Abused as a legitimate software-deployment vector via already-compromised IT-provider access
  • Google — Google Apps Script
    Vulnerable versions: Abused as a covert relay/proxy for C2 traffic; not a vulnerability in the service itself
  • Microsoft — Windows (DLL search-order / WinDirStat.exe sideloading path)
    Vulnerable versions: Abuse of DLL load order via a trojanized uxtheme.dll placed alongside a legitimate WinDirStat.exe

Remediation for Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based

Immediate actions

  • Block/alert on DNS queries and HTTPS traffic to studiotikva[.]com, api.studiotikva[.]com, m.studiotikva[.]com, hospitalinstallation[.]com and its subdomains, adserviceupdate[.]com, hygienehistory[.]com, and cloudlanecdn[.]com
  • Hunt for uxtheme.dll present outside %SystemRoot%\System32 alongside a WinDirStat.exe binary, and for the file listing C:\ProgramData\WinDir\WinDirStat.exe
  • Audit RMM/SysAid deployment logs for anomalous software-push events originating from IT-provider or MSP accounts
  • Review Microsoft Graph API audit logs for calendar events with anomalous future dates (e.g. year 2050) or unusual attachment patterns, and for anomalous application-token refresh activity
  • Hunt for outbound DNS queries with unusually structured subdomains (hex-like client IDs) to newly-registered or recently re-delegated domains

Workarounds

  • Disable or tightly restrict the 'search-ms:' URI handler and WebDAV client (davclnt.dll) where not operationally required
  • Block execution of Windows shortcut (.lnk) files delivered as email attachments or from WebDAV/network shares

Longer-term hardening

  • Deploy behavior-based EDR detection given the majority of Cavern Manticore binaries score zero or near-zero on static AV/VirusTotal detection
  • Enforce application allow-listing and DLL search-order hardening to reduce sideloading risk (uxtheme.dll, texture.dll, net.dll, rnp.dll style abuse)
  • Restrict and monitor use of Google Apps Script, Netlify, and similar low-cost hosting/automation platforms as sanctioned egress channels from corporate endpoints
  • Implement conditional access and anomaly detection on Microsoft Entra ID application credential refresh events
  • Train high-value personnel (nuclear-energy, defense, government, think-tank staff) on AI-enhanced spear-phishing pretexts (podcast/conference/interview invitations)

Timeline of Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based

  • studiotikva[.]com first registered, later reused as the Cavern/CAV3RN DNS-selection and Apps Script relay domain
  • Kaspersky begins ongoing monitoring of Project CAV3RN activity
  • studiotikva[.]com registration expires
  • Open-directory evidence indicates deployment of the APT42 SpearSpecter LNK spear-phishing campaign delivering the TAMECAT-linked loader chain
  • studiotikva[.]com re-registered via Dynadot Inc
  • APT42 SpearSpecter LNK samples submitted to VirusTotal from Sweden, UK, and Ukraine (through 27 May 2026)
  • DNS for studiotikva[.]com redelegated to RouterHosting LLC (ASN 14956)
  • HOLLOWGRAPH begins operating against Israeli mailboxes via Microsoft Graph calendar dead-drop
  • HOLLOWGRAPH module first detected
  • Check Point Research publishes 'Cavern Manticore: Exposing Iran-Linked Modular C2 Framework', detailing the modular Agent/module architecture and SysAid-abuse initial access
  • Last observed HOLLOWGRAPH communication among the 12 identified infected systems
  • Group-IB publishes HOLLOWGRAPH analysis of the Microsoft 365 calendar dead-drop mechanism
  • DarkAtlas publishes analysis tying APT42's AI-assisted phishing to an expanded TAMECAT backdoor
  • Kaspersky Securelist publishes 'Project CAV3RN continues', disclosing the DNS A-record channel-selection mechanism and Google Apps Script relay
  • The Hacker News publishes a consolidated summary of the Cavern/CAV3RN, HOLLOWGRAPH, and TAMECAT reporting

Sources cited for Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based

Threats related to Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based

Detection coverage for TL-2026-2053

As of 2026-08-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2053 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats