AI & TechBigTech CompaniesCybersecurityMENA Tech SceneNewswireTechnology

Iran-Linked Hacking Group Targets Israeli Government, IT Sectors

▼ Summary

– A new Iranian-linked cyber group, tracked as ‘Cavern Manticore’ by Check Point Research, has targeted Israeli government and IT organizations since early 2026.
– The group shares technical overlaps with known Iranian threat groups MuddyWater and Lyceum, which are linked to Iran’s Ministry of Intelligence and Security.
– Cavern Manticore uses a modular command-and-control (C2) framework built on a shared .NET foundation, consisting of a persistent backdoor agent and specialized post-exploitation modules.
– Initial access is typically gained by abusing remote monitoring and management (RMM) software or browser-based remote desktop tools to deliver malicious software disguised as legitimate updates.
– The modular C2 framework uses per-module AppDomain isolation to hinder forensic analysis, allowing attackers to minimize footprint and maintain persistence even if one component is detected.

Since early 2026, a new Iran-linked hacking group has been systematically targeting Israeli government agencies and IT organizations, according to a fresh analysis from Check Point Research. The Tel Aviv-based cybersecurity firm tracks this cluster under the name Cavern Manticore, noting significant technical overlaps with MuddyWater and Lyceum , two known threat groups tied to Iran’s Ministry of Intelligence and Security (MOIS).

Check Point researchers also identified that the group is deploying a previously undocumented modular command-and-control (C2) infrastructure. In a threat intelligence report published on July 6, the team highlighted the group’s ability to breach defense and government entities during the U. S. military campaign Operation Epic Fury. This, they noted, reflects both a high operational tempo and a disciplined approach to target selection.

Cavern Manticore’s initial access methods are notably opportunistic yet effective. The group commonly abuses existing remote monitoring and management (RMM) software to slip into target IT environments. From there, it moves laterally across victim networks, delivering malicious payloads disguised as legitimate software updates. Another favored vector involves browser-based remote desktop tools, such as remote printing, which allow data exfiltration even when clipboard-based copy-paste or file-transfer functions are locked down.

Once inside, the attacker triggers a SysAid software update process that installs malicious components onto the compromised system. To sustain its campaigns, Cavern Manticore relies on its own modular C2 framework, which researchers describe as “a mature and adaptable toolset built around a shared . NET foundation.”

This framework consists of two primary elements. The Cavern agent acts as a persistent backdoor, managing core communications with attacker-controlled servers. It uses multiple . NET compilation formats , including . NET Framework, . NET Mixed-Mode C++/CLI, and . NET Native AOT , to evade detection and complicate forensic analysis. The Cavern modules are specialized post-exploitation tools that handle tasks like reconnaissance, data theft, tunneling, and lateral movement. Each module is compiled separately, allowing the group to tailor attacks per victim.

To further frustrate defenders, the framework employs per-module AppDomain isolation. This prevents recovery of the full capability set from any single compromised host. The result is a system that minimizes the attacker’s footprint, allows for customized attacks, and maintains persistence , ensuring that even if one component is discovered, the rest remain hidden.

(Source: Infosecurity Magazine)

Topics

iranian cyber threat 95% cavern manticore group 92% modular c2 infrastructure 90% initial access vectors 88% cyber espionage 85% malicious software delivery 83% lateral movement 80% data exfiltration 78% detection evasion 76% post-exploitation tools 74%