INTEL_REPORT
The Hacker News · published 7/6/2026, 6:34:26 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations An Iranian hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular command-and-control (C2) framework dubbed Cavern (aka Cav3rn) targeting Israeli organizations. The activity, which has primarily singled out IT providers and government sectors, has been attributed to a threat cluster tracked by Check Point Research Ira…
https://thehackernews.com/2026/07/iran-linked-hackers-use-new-cavern-c2.html
sha256:c270af4e8a17635ed4f05f447211ceb9c70168226411a9a75edac339d9e11098
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| ode.dll |
| Open → |
| domain | n-ten.dll | Open → |
| domain | n-sws.dll | Open → |
| domain | hospitalinstallation.com | Open → |
| cve | CVE-2026-46817 | Open → |
| cve | CVE-2026-55200 | Open → |
| cve | CVE-2025-52691 | Open → |
| cve | CVE-2025-9316 | Open → |
| cve | CVE-2025-54068 | Open → |