BS Summary: This article contains 16 faulty reasoning types, including Post Hoc (False Cause), Unattributed Quote, and Representativeness Heuristic, with Appeal to Authority as the most egregious example at 25.9% saturation with 210 hits. Analysis detected 1,207 faulty-reasoning hits from 810 analyzed words, generating a BS Score of 32.8% and a BS Rank of 17% (18,173 of 21,887 articles). This article is better (less manipulative) than 83.00% of the article peer group.

An Iranian hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular command-and-control (C2) framework dubbed Cavern (aka Cav3rn) targeting Israeli organizations. 
The activity, which has primarily singled out IT providers and government sectors, has been attributed to a threat cluster tracked by Check Point Research under the moniker <b>Cavern Manticore</b>, which it said shares some level of tactical overlaps with MuddyWater and Lyceum, the latter of which is assessed to be a subgroup within OilRig. 
"The framework reflects a mature and adaptable toolset built around a shared . 
NET foundation, while using multiple compilation formats across different components, including . 
NET Framework, . 
NET Mixed-Mode C++/CLI, and . 
NET Native AOT," the cybersecurity company said. 
"The compilation format itself becomes the anti-analysis layer that forces reverse engineers into multiple toolsets and metadata-reconstruction workflows." 
The components of the C2 framework are used as Cavern Agent and Cavern modules, demonstrating a clear division of responsibilities between core communication capabilities and mission-specific post-exploitation functionality. 
This architecture has inherent advantages as it allows the operators to tailor deployments based on the victim profile, reduce forensic visibility, and ensure persistent access through bespoke modules for reconnaissance, data theft, tunneling, and lateral movement. 
The attack chain documented by Check Point Research commences with SysAid's software update feature, which is leveraged by the adversary to initiate a DLL side-loading chain that leads to the execution of a trojanized DLL ("uxtheme.dll") containing the Cavern Agent. 
The agent, for its part, loads a standalone communication DLL module ("n-HTCommp.dll") to contact the C2 server ("hospitalinstallation[.]com") and fetch additional post-exploitation modules on the fly over HTTPS or WebSocket. 
As many as five DLL modules have been uncovered - 
<ul> 
<li><b>mhm.dll</b>, for file operations, enumeration, recursive file search, archive handling, and bidirectional file transfer</li> 
<li><b>db.dll</b>, for SQL database enumeration, query, export, and manipulation</li> 
<li><b>ode.dll</b>, for Active Directory reconnaissance, user/group enumeration, and LDAP brute-force attempts</li> 
<li><b>n-ten.dll</b>, for network reconnaissance, port scanning, share enumeration, and SMB brute-force attempts</li> 
<li><b>n-sws.dll</b>, for SOCKS5 proxy and WebSocket tunneling</li> 
</ul> 
A defining trait of the framework is its use of three different . 
NET compilation targets spanning its components: while mhm.dll, db.dll, and ode.dll are pure . 
NET Framework modules, n-HTCommp.dll, n-ten.dll, and n-sws.dll make use of Native AOT (Ahead-of-Time) compilation. 
The main agent, uxtheme.dll, combines managed . 
NET code with native C++ in a single portable executable. 
Embedded within the agent is a unified module dispatcher that treats components whose names start with n- as native DLLs and loaded via the LoadLibraryA Windows API, while the rest is interpreted as managed . 
NET assemblies and loaded through a mechanism known as AppDomain isolation. 
"The framework's anti-analysis posture relies on uncommon . 
NET compilation formats (Mixed-Mode C++/CLI and Native AOT) that force reverse engineers into multiple toolsets and metadata-reconstruction workflows, together with per-module AppDomain isolation as an anti-forensics measure," Check Point explained. 
Attacks orchestrated by Cavern Manticore have involved the threat actor moving from an initial compromised IT provider to a second-hop provider before ultimately reaching the intended target organization, indicating their ability to weaponize trusted relationships in the software supply chain to their advantage. 
"This activity highlights the operational value of trusted service-provider relationships, particularly where Remote Monitoring and Management (RMM) solutions are deployed," the company noted. 
"By abusing these tools, the actor can move laterally between victims and deliver malicious software disguised as legitimate updates. 
The actor also appears to leverage browser-based remote desktop technologies to access targets of interest and, in some cases, abuse built-in features such as remote printing to exfiltrate data when clipboard-based copy-paste or file-transfer capabilities are restricted." 
The development unfolds against the backdrop of the ongoing joint military operation launched by Israel and the U.S. against Iran. 
In recent months, the Iranian state-sponsored threat actor tracked as MuddyWater has been observed conducting a broad reconnaissance campaign across more than 12,000 internet-exposed systems by exploiting known security flaws in internet-exposed SmarterMail, n8n, N-central, Langflow, and Laravel Livewire systems. 
The list of exploited vulnerabilities is as follows - 
<ul> 
<li><b>CVE-2025-52691</b> - SmarterMail remote code execution vulnerability</li> 
<li><b>CVE-2025-68613</b> - n8n remote code execution vulnerability</li> 
<li><b>CVE-2025-9316</b> - N-Central unauthenticated sessionID generation vulnerability</li> 
<li><b>CVE-2025-34291</b> - Langflow remote code execution vulnerability</li> 
<li><b>CVE-2025-54068</b> - Laravel Livewire remote code execution vulnerability</li> 
</ul> 
The operation is said to have pivoted from broad reconnaissance to targeted credential harvesting and data exfiltration attacks against aviation, energy, and government sectors in the Middle East, including aviation, energy, and public sector entities in Egypt, Israel, and the United Arab Emirates. 
"The operation leveraged a combination of vulnerability exploitation, Outlook Web Access (OWA) brute-force attacks, and newly identified command-and-control (C2) controllers supporting multi-protocol communication," Oasis Security said. 
"The activity progressed beyond reconnaissance and access attempts, resulting in confirmed exfiltration of sensitive data from compromised environments." 
Article reasoning-pattern comparisonThis article: 0.0%Ravie Lakshmanan: 1.5%The Hacker News: 1.9%Confirmation Bias0.0%This article: 0.0%Ravie Lakshmanan: 1.4%The Hacker News: 1.2%Anchoring Bias0.0%This article: 3.7%Ravie Lakshmanan: 2.4%The Hacker News: 3.3%Availability Heuristic3.7%This article: 12.0%Ravie Lakshmanan: 1.7%The Hacker News: 1.5%Representativeness Heuristic12.0%This article: 5.3%Ravie Lakshmanan: 0.9%The Hacker News: 0.6%Hindsight Bias5.3%This article: 10.5%Ravie Lakshmanan: 2.4%The Hacker News: 2.5%Overconfidence Bias10.5%This article: 6.9%Ravie Lakshmanan: 2.4%The Hacker News: 2.7%Framing Effect6.9%This article: 0.0%Ravie Lakshmanan: 0.8%The Hacker News: 1.0%Loss Aversion0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 0.6%Status Quo Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 4.4%Ravie Lakshmanan: 1.1%The Hacker News: 1.3%Optimism Bias4.4%This article: 4.6%Ravie Lakshmanan: 1.5%The Hacker News: 1.6%Pessimism Bias4.6%This article: 1.6%Ravie Lakshmanan: 7.7%The Hacker News: 6.7%Negativity Bias1.6%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.8%Self-Serving Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.6%The Hacker News: 0.4%Fundamental Attribution Error0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%Ravie Lakshmanan: 1.2%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 3.5%Ravie Lakshmanan: 0.3%The Hacker News: 0.6%Halo Effect3.5%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 4.9%Ravie Lakshmanan: 2.4%The Hacker News: 1.5%Recency Bias4.9%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.3%Primacy Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 25.9%Ravie Lakshmanan: 4.9%The Hacker News: 4.0%Appeal to Authority25.9%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 1.6%False Dilemma0.0%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 0.5%Slippery Slope0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Circular Reasoning0.0%This article: 9.5%Ravie Lakshmanan: 4.0%The Hacker News: 4.3%Hasty Generalization9.5%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.2%Bandwagon0.0%This article: 0.0%Ravie Lakshmanan: 1.1%The Hacker News: 1.1%Appeal to Emotion0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.5%Begging the Question0.0%This article: 22.5%Ravie Lakshmanan: 2.1%The Hacker News: 1.9%Post Hoc (False Cause)22.5%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 0.0%Ravie Lakshmanan: 0.9%The Hacker News: 0.6%Burden of Proof0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.3%Composition/Division0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 1.0%Anecdotal0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%No True Scotsman0.0%This article: 11.5%Ravie Lakshmanan: 3.8%The Hacker News: 2.3%Ambiguity (Equivocation)11.5%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 15.6%Ravie Lakshmanan: 3.4%The Hacker News: 1.4%Unattributed Quote15.6%This article: 0.0%Ravie Lakshmanan: 2.6%The Hacker News: 0.9%Quote-first Misdirection0.0%This article: 6.7%Ravie Lakshmanan: 2.5%The Hacker News: 2.3%Biased Writer Voice6.7%This article: 0.0%Ravie Lakshmanan: 2.4%The Hacker News: 4.4%Indoctrination0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 3.0%Attempt to Sell a Product or S…0.0%

810 words analyzed.

Speakers

2speakers6.9%attributed speech754writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 11 words • 0.0% coverageWriter's voice • 30 words • 0.0% coverageWriter's voice • 54 words • 100.0% coverageWriter's voice • 13 words • 100.0% coverageWriter's voice • 12 words • 100.0% coverageWriter's voice • 3 words • 100.0% coverageWriter's voice • 5 words • 100.0% coverageWriter's voice • 7 words • 100.0% coverageWriter's voice • 18 words • 100.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 36 words • 0.0% coverageWriter's voice • 40 words • 0.0% coverageWriter's voice • 30 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 35 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 8 words • 100.0% coverageCheck Point Research • 30 words • 0.0% coverageWriter's voice • 43 words • 0.0% coverageWriter's voice • 23 words • 100.0% coverageWriter's voice • 19 words • 100.0% coverageWriter's voice • 37 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 40 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 43 words • 0.0% coverageOasis Security • 26 words • 0.0% coverageWriter's voice • 18 words • 100.0% coverage
Selected voice

Check Point Research

100%flagged-word coverage
30 attributed words54% of attributed speech78% writer coverage
0%10.0%20.0%Unattributed Quote-16.7 ptsWriter: 16.7%Check Point Research: 0.0%0.0%Biased Writer Voice-7.2 ptsWriter: 7.2%Check Point Research: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.