highAPT

Cavern C2 Framework (Iran-linked MOIS-affiliated APT activity targeting Israel)

First seen Jul 7, 2026 · Updated Jul 7, 2026

irannation-statec2-frameworkmoisisraelgovernmentit-sectorcheck-point-research

A threat cluster linked to Iran's Ministry of Intelligence and Security (MOIS) has been observed using a previously undocumented modular command-and-control framework called Cavern (Cav3rn) to target Israeli IT providers and government organizations. Check Point Research attributes the activity to a state-sponsored espionage campaign aimed at establishing persistent access within high-value networks. The framework's modular design suggests ongoing development and long-term operational use by the threat actor.

Technical Analysis

Cavern is described as a modular C2 framework, indicating a plugin-based architecture that likely allows operators to extend capabilities such as reconnaissance, lateral movement, data exfiltration, and persistence without redeploying core malware components. The targeting of IT providers suggests a supply-chain-style access strategy, where compromising managed service or IT infrastructure providers grants downstream access to their government and enterprise clients. No specific CVEs, exploitation vectors, or encryption schemes were disclosed in the available reporting, limiting technical attribution to C2 architecture and targeting patterns rather than exploit mechanics. Organizations that rely on IT providers for managed services, including those hosting or operating AI agent infrastructure, RAG pipelines, or LLM tool-use environments, could face indirect compromise if their upstream IT/MSP provider is breached, potentially exposing API keys, credentials, or agent orchestration systems to the threat actor.

Affected Systems

IT service provider networks and government sector systems in Israel; specific software/OS versions not disclosed in available reporting

Indicators of Compromise

  • Not disclosed in available reporting (framework name: Cavern / Cav3rn)

Remediation Steps

  1. 1

    Monitor for Cavern C2 indicators

    Engage threat intelligence feeds (e.g., Check Point Research) for emerging IOCs, hashes, and network signatures associated with Cavern and apply them to SIEM/EDR detection rules.

  2. 2

    Harden IT/MSP supply chain access

    Review and restrict third-party IT provider access to critical government and enterprise networks; enforce least-privilege and network segmentation for MSP connections.

  3. 3

    Audit credential and API key exposure

    Rotate and audit credentials, API keys, and service accounts used by IT providers, especially those with access to systems running AI agents or automation pipelines.

  4. 4

    Enhance C2 traffic detection

    Deploy network monitoring for anomalous outbound connections, DNS tunneling, and beaconing patterns consistent with modular C2 frameworks.

  5. 5

    Sector-specific threat sharing

    Participate in ISAC/government threat-sharing programs to receive updated attribution and IOC data as Check Point Research publishes further findings.

Industries Most Exposed

governmentinformation technologymanaged service providers

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.