A reported campaign tied to an Iran-linked actor shows how a modular command-and-control stack and a foothold in IT service providers can turn trust into an attack path.
A reported campaign tied to Cavern Manticore combined a managed update workflow with Windows DLL sideloading, a reminder that the most useful enterprise tools can also become the cleanest routes for malware.
A reported Iran-linked cluster is using a modular .NET command-and-control framework for reconnaissance and lateral movement, showing how modern implants can hide behind ordinary software patterns.