CVE

CVE-2025-54068

Livewire vulnerable to remote command execution during property update hydration

Exploitation IoCs 12

Domain hospitalinstallation[[.]]com
Domain tracker[.]js
Filename db.dll
Filename mhm.dll
Filename n-HTCommp.dll
Filename n-sws.dll
Filename n-ten.dll
Filename ode.dll
Filename tracker.js
Filename uxtheme.dll
GitHub Repo ChocoPoC
Package skytext

MITRE ATT&CK TTPs 125

T1003
OS Credential Dumping
Credential Access
T1005
Data from Local System
Collection
T1021
Remote Services
Lateral Movement
T1021.001
Remote Desktop Protocol
Lateral Movement
T1021.002
SMB/Windows Admin Shares
Lateral Movement
T1021.003
Distributed Component Object Model
Lateral Movement
T1021.004
SSH
Lateral Movement
T1021.005
VNC
Lateral Movement
T1021.006
Windows Remote Management
Lateral Movement
T1021.007
Cloud Services
Lateral Movement
T1021.008
Direct Cloud VM Connections
Lateral Movement
T1021.009
T1021.009
T1021.010
T1021.010
T1021.011
T1021.011
T1021.012
T1021.012
T1021.013
T1021.013
T1021.014
T1021.014
T1021.015
T1021.015
T1021.016
T1021.016
T1021.017
T1021.017
T1021.018
T1021.018
T1021.019
T1021.019
T1021.020
T1021.020
T1021.021
T1021.021
T1021.022
T1021.022
T1021.023
T1021.023
T1021.024
T1021.024
T1021.025
T1021.025
T1021.026
T1021.026
T1021.027
T1021.027
T1021.028
T1021.028
T1021.029
T1021.029
T1021.030
T1021.030
T1021.031
T1021.031
T1021.032
T1021.032
T1021.033
T1021.033
T1021.034
T1021.034
T1021.035
T1021.035
T1021.036
T1021.036
T1021.037
T1021.037
T1021.038
T1021.038
T1021.039
T1021.039
T1021.040
T1021.040
T1021.041
T1021.041
T1021.042
T1021.042
T1021.043
T1021.043
T1021.044
T1021.044
T1021.045
T1021.045
T1021.046
T1021.046
T1021.047
T1021.047
T1021.048
T1021.048
T1021.049
T1021.049
T1021.050
T1021.050
T1021.051
T1021.051
T1021.052
T1021.052
T1021.053
T1021.053
T1021.054
T1021.054
T1021.055
T1021.055
T1021.056
T1021.056
T1021.057
T1021.057
T1021.058
T1021.058
T1021.059
T1021.059
T1021.060
T1021.060
T1021.061
T1021.061
T1021.062
T1021.062
T1021.063
T1021.063
T1021.064
T1021.064
T1021.065
T1021.065
T1021.066
T1021.066
T1021.067
T1021.067
T1021.068
T1021.068
T1021.069
T1021.069
T1021.070
T1021.070
T1021.071
T1021.071
T1021.072
T1021.072
T1021.073
T1021.073
T1021.074
T1021.074
T1021.075
T1021.075
T1021.076
T1021.076
T1021.077
T1021.077
T1021.078
T1021.078
T1021.079
T1021.079
T1021.080
T1021.080
T1021.081
T1021.081
T1021.082
T1021.082
T1021.083
T1021.083
T1021.084
T1021.084
T1021.085
T1021.085
T1021.086
T1021.086
T1021.087
T1021.087
T1021.088
T1021.088
T1021.089
T1021.089
T1021.090
T1021.090
T1021.091
T1021.091
T1021.092
T1021.092
T1021.093
T1021.093
T1021.094
T1021.094
T1021.095
T1021.095
T1021.096
T1021.096
T1021.097
T1021.097
T1021.098
T1021.098
T1021.099
T1021.099
T1021.100
T1021.100
T1027
Obfuscated Files or Information
Defense Evasion
T1027.002
Software Packing
Defense Evasion
T1048
Exfiltration Over Alternative Protocol
Exfiltration
T1053.005
Scheduled Task
Execution
T1055
Process Injection
Defense Evasion
T1056.001
Keylogging
Collection
T1059.001
PowerShell
Execution
T1059.005
Visual Basic
Execution
T1070.004
File Deletion
Defense Evasion
T1071
Application Layer Protocol
Command And Control
T1071.001
Web Protocols
Command And Control
T1071.002
File Transfer Protocols
Command And Control
T1071.003
Mail Protocols
Command And Control
T1071.004
DNS
Command And Control
T1078
Valid Accounts
Defense Evasion
T1082
System Information Discovery
Discovery
T1085
T1085
T1090
Proxy
Command And Control
T1095
Non-Application Layer Protocol
Command And Control
T1105
Ingress Tool Transfer
Command And Control
T1114.001
Local Email Collection
Collection
T1484.002
Trust Modification
Defense Evasion

Source Articles

Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
An Iranian hacking group linked to the Ministry of Intelligence and Security (MOIS), tracked as Cavern Manticore, has been using a new modular command-and-control (C2) framework named Cavern to target Israeli organizations, particularly in the IT and government sectors. The attack leverages DLL side-loading via SysAid's software update mechanism, deploying a trojanized DLL (uxtheme.dll) that communicates with a C2 server and downloads additional malicious modules. These modules enable reconnaissance, data theft, lateral movement, and tunneling, with a sophisticated .NET-based architecture using mixed compilation formats to hinder analysis. The group exploits trusted relationships in the software supply chain and has shifted from broad reconnaissance to targeted data exfiltration across Middle Eastern sectors.
hacker-news Jul 6, 2026
⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
The article covers multiple cyber threats including the disruption of the NetNut residential proxy network, which leveraged compromised home devices to route malicious traffic. Threat actors are targeting researchers with fake proof-of-concept repositories delivering the ChocoPoC RAT, while the Scattered Spider group is linked to extortion attempts. New malware such as Ousaban and browser-based ransomware exploit social engineering and legitimate browser APIs, and AI-driven attacks are increasing in sophistication, including indirect prompt injection and fake phishing pages generated via AI.
hacker-news Jul 6, 2026