Adversary Intelligence — 2026-07-07
Check Point Identifies New MOIS-Linked Cyber Group Cavern Manticore Targeting Israeli Government Through IT Supply Chain
BLUFCavern Manticore's abuse of trusted RMM tools and provider-to-provider pivoting will likely yield further compromises of Israeli government networks through at least the third quarter, as no single vendor fix closes the pathway.
Check Point Research disclosed a new modular command-and-control framework called Cavern, used by an Iran-nexus threat actor it tracks as Cavern Manticore against Israeli government and IT-sector targets since early 2026 1. In one documented intrusion, the group abused SysAid's legitimate software-deployment feature to push a compromised WinDirStat binary and side-load malicious code, though Check Point stated SysAid itself was not breached and no SysAid vulnerability was exploited 12. The actor gained initial footholds by abusing Remote Monitoring and Management software already installed at IT providers, in several cases pivoting from one compromised provider to another before reaching a government network 13. Check Point assessed technical overlaps between Cavern Manticore and other MOIS-linked groups including MuddyWater and Lyceum, and reported that most observed samples returned zero or very low detection rates on VirusTotal 12. The Hacker News and the Jerusalem Post both relayed the Check Point findings, with the Jerusalem Post noting the report was released Monday 34.
AnalysisCavern Manticore's abuse of trusted RMM tools and provider-to-provider pivoting exposes a repeatable IT supply-chain pathway into Israeli government networks that patching a single vendor cannot close, and continued targeting of Israeli IT providers and government entities through at least the third quarter is
likely given tradecraft overlaps with MuddyWater and Lyceum and near-zero VirusTotal detection rates. Confidence is moderate: the finding rests on one technical disclosure with strong forensic detail, relayed without independent verification by The Hacker News and Jerusalem Post, and no confirmed follow-on compromise beyond the documented intrusion chain. The overlaps could just as easily reflect shared Iranian contractor tooling or leaked frameworks rather than a distinct centrally directed group, leaving defenders and providers to decide now whether to mandate enhanced RMM monitoring and provider segmentation or wait for confirmed exploitation elsewhere.
4 sources
- Cavern Manticore: Exposing Iran-Linked Modular C2 Framework - Check Point Research
- New Iran-Linked Hacker Group Cavern Manticore Targets Israeli Government via IT Supply Chain - The Defense News
- Iran-linked hacker group Cavern Manticore targets Israeli IT, government sectors - The Jerusalem Post
- Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations - The Hacker News
View in full brief →