This weekly threat intelligence bulletin covers multiple significant incidents including autonomous LLM-driven ransomware (JadePuffer), a cryptocurrency supply chain compromise via malicious npm packages, and three critical CVEs affecting Langflow, Tenda routers, and Linux KVM. Iran-linked Cavern Manticore and China-linked UAT-7810 were profiled targeting Israeli and networking infrastructure respectively. The report also highlights risks in AI development tools where hidden malicious instructions in open-source files could achieve RCE through Claude Code and OpenAI Codex.
Cavern Manticore
2 posts
13th July – Threat Intelligence Report Cavern Manticore: Exposing Iran-Linked Modular C2 Framework Cavern Manticore, an Iran-MOIS-linked APT group, deploys a modular .NET C2 framework targeting Israeli government and IT organizations. The framework uses three compilation formats (Mixed-Mode C++/CLI, NativeAOT, .NET Framework) as an anti-analysis layer, with DLL sideloading via WinDirStat.exe for initial execution. Post-exploitation modules provide DPAPI decryption, LDAP brute-forcing, SQL browsing, network reconnaissance, and SOCKS5 tunneling, with C2 traffic XOR-encrypted over HTTPS/WebSocket channels.