New Cavern C2: an Iranian attack via SysAid and DLL side-loading targets Israeli organisations

Colleagues, I’d like to flag an important cyber security story.
I came across Cavern, a new modular C2 framework linked to an Iranian group targeting Israeli organisations.
Key points:
- the intrusion leveraged SysAid updates and DLL side-loading;
- targets included IT providers and the public sector;
- separate modules handled reconnaissance, data theft, tunnelling and lateral movement;
- analysis is complicated by multiple .NET formats, including Mixed-Mode and Native AOT.
Why it matters: campaigns like this show how dangerous supply-chain trust and unmanaged RMM tools can be.
How do you assess the risk of attacks routed through vendors?
#cybersecurity #ThreatIntelligence #Malware #APT

