Iran-linked attackers target Israeli firms with Cavern malware
Iran-linked attackers use a new spy tool called Cavern to break into Israeli companies. It steals data and lets attackers control infected computers.
- Report priority
- Medium
How it works
Attackers send a fake email or infected file to trick employees into opening it, which installs Cavern malware on their work computer.
What to do
Check if your work computer has been infected by looking for unusual network activity or unexpected files in your downloads folder.
Update your antivirus software and report any suspicious emails or files to your IT team immediately.
Technical details
An Israeli employee clicks a link in a fake invoice email. The link downloads a hidden program that secretly connects to a remote server. The attackers then use that link to spy on the employee's work files and send stolen data back to Iran.
Check Point Research tracks the operators as Cavern Manticore, a cluster overlapping with MuddyWater and Lyceum (a OilRig subgroup). The Cavern framework mixes.NET Framework, Mixed-Mode C++/CLI, and Native AOT compiled components specifically to slow down reverse engineers, and isolates each module in its own AppDomain to limit forensic traces. The main agent, uxtheme.dll, is side-loaded via a trojanized SysAid update chain and talks to over HTTPS or WebSocket, then pulls down modules for file operations, SQL database abuse, Active Directory and network reconnaissance, and SOCKS5 tunneling.