Check Point Research, an Israeli cybersecurity company, disclosed in a report released on Monday, July 6, 2026, that an Iran-linked hacking group developed a new framework to target Israeli organizations in the government and information technology sectors.
The company has been monitoring the hacking group, named Cavern Manticore, since early 2026. Check Point Research stated that the group is linked to the Iranian Ministry of Intelligence and Security. The new framework allows hackers to customize attacks for different environments. This framework is designed to limit the information defenders and analysts can recover from any single victim and to extend access after an initial attack through specialized modules for expansion and data access.
According to the report, Cavern Manticore initially attacked and utilized trusted IT providers to distribute its new tool. Once installed, the tool can infiltrate programs used to access other computers, allowing malware disguised as legitimate updates from an IT provider to be delivered to a customer. The tool appeared to be specifically designed to exploit Remote Monitoring and Management (RMM) solutions, which enable control of a device to be transferred to another party.
The tool gained access to files on infected computers, downloaded additional programs, searched files and internal networks, tested passwords, and moved deeper into targeted organizations. Check Point Research found multiple instances where an initially compromised provider led to another before the tool reached its intended target. Check Point Research stated these findings suggest that Cavern Manticore has a detailed understanding of the IT supplier chains within Israel.
Check Point Research warned that Cavern Manticore demonstrated Iranian cyber capabilities. The company added that the system can rapidly adapt to new campaigns, targets, and operational requirements.
forum Comments (0)
No comments yet. Be the first to comment.