Actor Profile
Cavern (aka Cav3rn) is a command-and-control framework attributed to Iranian nation-state threat actors, specifically linked to Cavern Manticore, a hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS). The group shares operational overlaps with MuddyWater and the OilRig sub-group Lyceum. Kaspersky has linked the framework to OilRig (APT34) with low confidence based on behavioral patterns including use of Microsoft-hosted services for C2, secondary OAuth token recovery mechanisms, and use of compromised infrastructure in targeted regions. The actor's motivation centers on intelligence collection and cyber espionage operations against Israeli government, defense, and critical infrastructure entities.
TTPs (Tactics, Techniques, Procedures)
The Cavern framework employs a modular, plugin-based architecture that became operational in late April 2026. Key TTPs include: DNS tunneling for credential refresh and C2 channel selection (T1071.004); abuse of legitimate cloud services including Google Apps Script relay and Microsoft 365 Graph API for C2 communication (T1102); covert channels using Microsoft 365 calendar events as dead-drops with events dated to 2050 to avoid detection (T1102.002); HTTPS-based C2 with dynamic channel switching via DNS A-record queries; file exfiltration through encrypted calendar event attachments; post-exploitation modules for file operations, SQL database enumeration, Active Directory reconnaissance (T1018, T1087), LDAP brute-force attacks (T1110), network reconnaissance, and SOCKS5 proxy/WebSocket tunneling (T1090). The framework includes inter-component broker functionality for runtime upgrades and component orchestration. Infrastructure includes expired and re-registered domains (studiotikva[.]com) and compromised legitimate infrastructure in target regions.
Targets & Patterns
Primary targeting focuses on Israeli entities across government, defense, and critical infrastructure sectors. The actor demonstrates strategic interest in high-value intelligence collection from organizations with national security relevance. The use of compromised infrastructure belonging to entities in regions it targets suggests the actor conducts reconnaissance and establishes footholds within trusted network perimeters to facilitate lateral movement and evade detection. The operational tempo and continuous framework evolution since December 2025 indicates sustained, focused intelligence collection requirements against Israeli targets. The related APT42 activity targeting nuclear energy sector individuals in April-May 2026 demonstrates broader Iranian cyber espionage priorities extending to strategic industries.
Historical Context
Cavern was first publicly documented by Check Point Research in July 2026, with Kaspersky tracking the activity cluster since December 2025. The framework's modular architecture shift occurred in late April 2026. Follow-up reports from Group-IB and Kaspersky in mid-2026 detailed the HOLLOWGRAPH module (first detected June 7, 2026) that abuses Microsoft 365 calendars for C2. The primary domain studiotikva[.]com was originally registered in February 2024, expired in February 2026, and was re-registered three months later in May 2026, indicating operational continuity despite infrastructure disruption. The framework shows tactical similarities to historical OilRig/APT34 operations including RDAT, OilCheck, OilBooster, Solar, and Veaty malware campaigns, particularly in the abuse of Microsoft-hosted services and secondary token recovery mechanisms. The August 2026 discovery of GoogleService.dll represents the latest evolution in the framework's communication capabilities.
Defensive Recommendations
- Monitor DNS A-record queries to suspicious domains for anomalous patterns that may indicate C2 channel selection logic; implement DNS query logging and baseline normal query behavior
- Detect abuse of Google Apps Script and Microsoft Graph API through anomalous OAuth token usage, unusual API call patterns to calendar services, and calendar events with future dates (e.g., 2050) containing file attachments (T1102.002)
- Implement behavioral detection for DNS tunneling activity (T1071.004) by monitoring for high-frequency DNS queries, unusual subdomain lengths, and entropy analysis of DNS request patterns
- Monitor for .NET NativeAOT-compiled DLLs with unusual inter-process communication patterns, particularly DLLs acting as component brokers (rnp.dll pattern) that load multiple modules and route messages between them
- Establish baseline for legitimate cloud service usage and alert on deviations including HTTPS connections to Google Apps Script deployments from unexpected hosts, and Microsoft 365 mailbox access from unusual geolocations or user agents
---
# Geopolitical Context
Geopolitical Context
The continued development of the Cavern framework reflects Iran's sustained cyber intelligence collection priorities against Israeli government, defense, and critical infrastructure targets. The activity is attributed to threat actors linked to Iran's Ministry of Intelligence and Security (MOIS), operating under designations including Cavern Manticore, MuddyWater, and elements of OilRig/APT34. The framework's evolution—from direct C2 channels to abuse of Microsoft 365 calendars and now Google Apps Script relays—demonstrates adaptive tradecraft designed to circumvent network defenses and complicate attribution. This operational tempo is consistent with broader Iranian cyber doctrine emphasizing persistent access, intelligence collection, and pre-positioning in adversary networks. The targeting of Israeli entities aligns with longstanding geopolitical tensions between Tehran and Jerusalem, particularly amid ongoing regional security dynamics involving nuclear negotiations, proxy conflicts, and mutual cyber operations. Parallel APT42 activity targeting the nuclear energy sector underscores Iran's prioritization of strategic intelligence on proliferation-sensitive technologies.
State Actor Alignment
The Cavern framework is attributed to Iranian state-sponsored actors affiliated with the Ministry of Intelligence and Security (MOIS), specifically the Cavern Manticore group, which overlaps with MuddyWater and the OilRig sub-group Lyceum. Kaspersky assesses low-confidence linkage to OilRig/APT34 based on tactical similarities, including abuse of Microsoft-hosted services for C2 (RDAT, OilCheck), secondary OAuth token recovery mechanisms (OilBooster), and use of compromised regional infrastructure. APT42, separately disclosed by DarkAtlas, is also an MOIS-affiliated group conducting parallel intelligence collection against nuclear sector targets. Iranian cyber units remain subject to U.S., EU, and allied sanctions frameworks targeting MOIS and Islamic Revolutionary Guard Corps (IRGC) cyber elements. The operational infrastructure—including domains like studiotikva[.]com—appears designed to mimic Israeli or regional entities, consistent with Iranian targeting doctrine.
Business Impacty pro region
The targeting of Israeli government, defense, and critical infrastructure entities represents a direct cyber threat to a key U.S. Middle East ally and regional security partner. Israeli cybersecurity agencies, including the National Cyber Directorate, are likely prioritizing detection and mitigation of Cavern-related intrusions, particularly given the framework's emphasis on persistence and credential harvesting in Active Directory environments. For European allies, the abuse of widely deployed platforms—Microsoft 365, Google Apps Script—to disguise C2 traffic poses detection challenges for organizations using similar cloud services, potentially complicating threat hunting and incident response. The nuclear sector targeting by APT42 may concern European states involved in Iran nuclear diplomacy (E3: France, Germany, UK) and International Atomic Energy Agency (IAEA) monitoring. Broader implications include the normalization of cloud service abuse for state-sponsored espionage, which may prompt policy discussions on platform provider responsibilities, threat intelligence sharing, and collective defense measures within NATO and EU cyber frameworks.
Forecast
If Iranian operators continue expanding Cavern's modular architecture and cloud service abuse techniques, defenders should anticipate further diversification of C2 channels, potentially incorporating additional legitimate SaaS platforms to evade detection. The framework's rapid development pace—transitioning to modular plugins by April 2026 and adding Google Apps Script relays by August 2026—suggests iterative capability enhancement is likely to persist. Organizations in Israel and allied nations with exposure to Iranian cyber operations should expect sustained targeting of government, defense, and critical infrastructure sectors, particularly entities involved in regional security, energy, and technology. If geopolitical tensions between Iran and Israel escalate—whether through kinetic operations, nuclear negotiations, or proxy conflicts—cyber activity attributed to MOIS-affiliated groups may intensify in scope and aggression. Defensive measures should prioritize anomaly detection in cloud service usage, DNS traffic analysis, and monitoring for OAuth token abuse. If platform providers enhance detection of C2 abuse, Iranian operators may shift to alternative legitimate services or encrypted communication channels, requiring adaptive threat intelligence and public-private collaboration.
