Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based Channel Selection and Google Apps Script Relay — Threadlinqs Intelligence
As of 2026-08-17, Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based Channel Selection and Google Apps Script Relay is a high-severity malware threat attributed to Cavern Manticore (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 28 indicators of compromise.
Threat ID: TL-2026-2053 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Cavern Manticore · Iran · ESPIONAGE
Iran-linked cluster Cavern Manticore (aka Cav3rn, MOIS-affiliated, overlapping MuddyWater and OilRig sub-group Lyceum) has evolved its modular CAV3RN C2 framework to query DNS A-records under
Cavern Manticore (previously tracked under the leetspeak name Cav3rn) is an Iran-nexus threat cluster, assessed as MOIS-affiliated, whose CAV3RN command-and-control framework has been under research-community observation since at least December 2025 (Kaspersky) with a major public disclosure by Check Point Research on 6 July 2026. The framework is modular and plugin-based: an Agent component (`uxtheme.dll`, DLL-sideloaded via a trojanized WinDirStat.exe execution path) loads functional modules for file operations (`mhm.dll`), SQL database access (`db.dll`), LDAP/Active Directory reconnaissance including credential brute-force (`ode.dll`), network reconnaissance (`n-ten.dll`), and SOCKS5/WebSocket tunneling (`n-sws.dll`). Modules are compiled in a deliberate mix of pure .NET Framework (IL-only), Mixed-Mode C++/CLI, and .NET 8 NativeAOT builds, a strategy that raises reverse-engineering cost per sample and keeps most binaries at zero or near-zero AV detection on VirusTotal. Initial access in the Check Point-documented campaign involved abuse of a legitimate SysAid RMM software-deployment feature, consistent with multi-hop compromise through a trusted IT-provider relationship before reaching Israeli government and IT-sector victims.
As of the August 2026 disclosure (Kaspersky Securelist, 'Project CAV3RN continues', 11 August 2026), the communications layer has been rearchitected around a new domain, studiotikva[.]com (first registered February 2024, allowed to expire February 2026, then re-registered 12 May 2026 via Dynadot and re-delegated to RouterHosting LLC infrastructure on 19 May 2026). The updated communication module (`GoogleService.dll`, .NET 8 NativeAOT) and an inter-component broker (`rnp.dll`, masquerading as the RNP OpenPGP library) query DNS A-records at `<nonce><error-state>.<hex-client-id>.m.studiotikva[.]com` before each transaction; the fourth octet of the returned address is a compact control signal that selects a direct HTTPS request to `api.studiotikva[.]com/api/v1/update/check`, a POST to a Google Apps Script deployment at `script.google[.]com/macros/s/{deployment-ID}/exec` acting as a relay to the real backend, or transaction termination, depending on the octet value and the module's tracked error state. The malware can validate whether its Apps Script deployment ID is stale by comparing a digest against a DNS response, and pull a replacement ID via small chunked DNS responses, letting operators rotate the Google-fronted relay without redeploying the implant. To ordinary network monitoring this traffic resembles legitimate access to a Google-hosted automation service.
A companion module, HOLLOWGRAPH (.NET NativeAOT DLL, first observed operating 3 June-9 July 2026 and reported by Group-IB), abuses the Microsoft Graph API through a compromised Microsoft 365 mailbox, treating the account's calendar as a two-way dead-drop: operators plant tasking as calendar events dated far in the future (2050-05-13), and the implant reads 'get'/'send' commands and exfiltrates staged files as encrypted calendar attachments, secured with hybrid RSA-OAEP/AES-256-GCM using separate key pairs for inbound and outbound traffic. A secondary DNS-tunneling channel to cloudlanecdn[.]com refreshes Microsoft Entra ID application credentials (tenant ID, client ID, client secret, mailbox) in small AAAA-record chunks, writing results to a local `logAzure.txt`. Group-IB identified at least 12 HOLLOWGRAPH-infected systems (3 actively communicating), all consistent with Israeli targeting, and noted technical overlap with Lyceum at low-to-medium confidence.
The broader toolset referenced alongside Cavern/CAV3RN includes TAMECAT, a modular PowerShell-based surveillance/collection framework associated with Iran-linked APT42 (closely associated with TA453) and analyzed by DarkAtlas. TAMECAT performs host/network discovery, arbitrary command execution, browser credential and cookie theft (targeting Edge/Chrome via the DevTools Protocol), Outlook
Target sectors: government administration, it services msp, nuclear energy, defense
Target regions: israel, united states of america, Middle East
Timeline
- studiotikva[.]com first registered, later reused as the Cavern/CAV3RN DNS-selection and Apps Script relay domain
- Kaspersky begins ongoing monitoring of Project CAV3RN activity
- studiotikva[.]com registration expires
- Open-directory evidence indicates deployment of the APT42 SpearSpecter LNK spear-phishing campaign delivering the TAMECAT-linked loader chain
- studiotikva[.]com re-registered via Dynadot Inc
- APT42 SpearSpecter LNK samples submitted to VirusTotal from Sweden, UK, and Ukraine (through 27 May 2026)
- DNS for studiotikva[.]com redelegated to RouterHosting LLC (ASN 14956)
- HOLLOWGRAPH begins operating against Israeli mailboxes via Microsoft Graph calendar dead-drop
- HOLLOWGRAPH module first detected
- Check Point Research publishes 'Cavern Manticore: Exposing Iran-Linked Modular C2 Framework', detailing the modular Agent/module architecture and SysAid-abuse initial access
- Last observed HOLLOWGRAPH communication among the 12 identified infected systems
- Group-IB publishes HOLLOWGRAPH analysis of the Microsoft 365 calendar dead-drop mechanism
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 28 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583.001, T1566.001, T1204.002, T1218.011, T1574.001, T1547.001, T1027, T1140, T1110, T1555.003