VMTech
Discuss a project

New Cavern C2: an Iranian attack via SysAid and DLL side-loading targets Israeli organisations

New Cavern C2: an Iranian attack via SysAid and DLL side-loading targets Israeli organisations

Colleagues, I’d like to flag an important cyber security story.

I came across Cavern, a new modular C2 framework linked to an Iranian group targeting Israeli organisations.

Key points:
- the intrusion leveraged SysAid updates and DLL side-loading;
- targets included IT providers and the public sector;
- separate modules handled reconnaissance, data theft, tunnelling and lateral movement;
- analysis is complicated by multiple .NET formats, including Mixed-Mode and Native AOT.

Why it matters: campaigns like this show how dangerous supply-chain trust and unmanaged RMM tools can be.

How do you assess the risk of attacks routed through vendors?

#cybersecurity #ThreatIntelligence #Malware #APT

Open analytics
On the site 2 views
min read 1 06.07.2026
On Instagram 11 views
On Instagram 1 reach
Instagram

New Cavern C2: an Iranian attack via SysAid and DLL side-loading targets Israeli organisations

Open the post on Instagram ↗