What happened
A hacking cluster tied to Iran's Ministry of Intelligence and Security has deployed a previously unknown modular command-and-control framework, referred to as Cavern or Cav3rn, against Israeli IT providers and government bodies. The operation was uncovered and attributed by Check Point Research, which identified the tooling as purpose-built for persistent, stealthy access across targeted networks. Separately, the FBI coordinated with industry partners to seize hundreds of domains belonging to NetNut, a residential proxy service operated by Nasdaq-listed Israeli firm Alarum Technologies. Investigators connected NetNut's infrastructure to the Popa botnet, a finding that Krebs on Security had surfaced roughly two weeks before the seizure.
Why it matters for your business
The Cavern campaign illustrates how nation-state actors are investing in bespoke, modular tooling that sidesteps signature-based detection—making managed IT providers a particularly high-value entry point into downstream clients. Any organisation that relies on third-party IT services should treat those vendors as part of its own attack surface and demand evidence of regular penetration testing and network segmentation. The NetNut seizure carries a separate but equally urgent lesson: legitimate-looking residential proxy services can be quietly routing traffic through compromised consumer devices, meaning that corporate threat-intelligence feeds and blocklists may be badly out of date if they exclude residential IP ranges. Security teams should audit which proxy or anonymisation services touch their data pipelines and validate that those providers have clean legal and infrastructure histories.
What to watch next
Analysts will be monitoring whether other Alarum Technologies products or subsidiary services show signs of botnet entanglement following the NetNut seizure, and whether the FBI action prompts further scrutiny of the residential proxy industry more broadly. On the espionage front, the modular architecture of Cavern suggests additional plugins or sub-campaigns may surface; security vendors tracking this Iranian cluster are likely to release updated indicators of compromise in the coming weeks. Organisations operating in sectors adjacent to Israeli government contracting should treat the next 60 days as an elevated-alert window.
