0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

New Iran-Linked Hacking Group Cavern Manticore Targets Israeli Government and IT Sectors (infosecurity-magazine.com)

· 21d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Cavern Manticore targets Israeli government and IT organizations.
  • The group uses a modular C2 framework with two main components.
  • Technical overlaps with Iran-linked groups MuddyWater and Lyceum.
  • Detection rate on VirusTotal is often zero or very low.
  • Initial access via RMM software and browser-based remote desktop tools.

"Check Point Research has identified a new cyber adversary tracked as 'Cavern Manticore', linked to Iran, targeting Israeli government and IT organizations since early 2026. The group uses a modular command-and-control (C2) framework, with technical overlaps with MuddyWater and Lyceum, both attributed to Iran's Ministry of Intelligence and Security (MOIS). Initial access is gained by abusing remote monitoring and management (RMM) software and browser-based remote desktop tools. The C2 framework consists of Cavern agent (persistent backdoor) and Cavern modules (specialized post-exploitation tools). Most samples show zero or very low detection on VirusTotal."

Discussion Matrix

0 segments

no comments yet.