Iranian hackers have turned the usual tools of system administrators into a path to secure networks. The Cavern Manticore group uses the new modular platform Cavern to attack Israeli government agencies and IT companies, Check Point experts have found. In some cases, the attackers first hacked IT service providers, and then through their infrastructure got to more important goals.
Cavern Manticore activity has been monitored since the beginning of 2026. The group is associated with the Ministry of Intelligence and National Security of Iran, and its tools have common features with the developments of MuddyWater and Lyceum. To penetrate the network for the first time, hackers abused remote control systems already established in organizations, so malicious activity could look like the usual work of administrators.
Having penetrated the network, the attackers launched the Cabern. The platform consists of a main agent and individual modules that operators load depending on the task. This approach allows you to study the internal network, work with files and databases, search for users and computers in the domain, check the account data and create tunnels to access further.
The developers of Cavern paid special attention to ensuring that the platform was more difficult to analyze. The components of the platform are written on . NET, but collected in three different formats. To study each option, specialists have to use individual tools and methods. Some modules also hide important lines and system functions until the launch, which makes it more difficult to check files automatically. Most of the samples found were hardly detected by antivirus systems.
Additionally protects the platform of how modules start. Cavern places each component in a separate memory area, performs the desired task, and then unloads it. After the work is completed, there are fewer traces left in the memory that the safety specialists could study. The platform also knows how to update its own components and remove previously congested modules before the new session.
Experts have discovered modules that manage files, browse databases, study Active Directory, conduct reconnaissance inside the network and create proxy tunnels. One of the components allows you to decrypt the protected user data, the other checks pairs of logins and passwords to gain access to network resources. Operators can select a set of tools for each victim and not disclose the entire platform if they find one infected computer.
The code analysis also showed that Cabern was developed gradually. Earlier versions were called Cav3rn and were major monolithic programs. Later, the developers shared the capabilities between individual modules, added new ways of communication with server control servers and made components more difficult to analyze.
Check Point links Cavern Manticore to Iran by a combination of technical features, infrastructure and similarities with previous operations. The group mainly attacks Israeli government agencies and IT companies. In several cases, a hacked service provider served only as an intermediate on the way to a more valuable organization.
The campaign shows that trusted remote control tools are becoming a convenient channel for hidden attacks. Cavern Manticore uses the legitimate access of IT service providers to move between organizations and mask malicious actions for conventional administration. The Cavern’s modular architecture further prevents attacks from detecting attacks in time, as hackers can quickly change the set of tools, maintaining the main platform and access to the infected infrastructure.
Cavern Manticore activity has been monitored since the beginning of 2026. The group is associated with the Ministry of Intelligence and National Security of Iran, and its tools have common features with the developments of MuddyWater and Lyceum. To penetrate the network for the first time, hackers abused remote control systems already established in organizations, so malicious activity could look like the usual work of administrators.
Having penetrated the network, the attackers launched the Cabern. The platform consists of a main agent and individual modules that operators load depending on the task. This approach allows you to study the internal network, work with files and databases, search for users and computers in the domain, check the account data and create tunnels to access further.
The developers of Cavern paid special attention to ensuring that the platform was more difficult to analyze. The components of the platform are written on . NET, but collected in three different formats. To study each option, specialists have to use individual tools and methods. Some modules also hide important lines and system functions until the launch, which makes it more difficult to check files automatically. Most of the samples found were hardly detected by antivirus systems.
Additionally protects the platform of how modules start. Cavern places each component in a separate memory area, performs the desired task, and then unloads it. After the work is completed, there are fewer traces left in the memory that the safety specialists could study. The platform also knows how to update its own components and remove previously congested modules before the new session.
Experts have discovered modules that manage files, browse databases, study Active Directory, conduct reconnaissance inside the network and create proxy tunnels. One of the components allows you to decrypt the protected user data, the other checks pairs of logins and passwords to gain access to network resources. Operators can select a set of tools for each victim and not disclose the entire platform if they find one infected computer.
The code analysis also showed that Cabern was developed gradually. Earlier versions were called Cav3rn and were major monolithic programs. Later, the developers shared the capabilities between individual modules, added new ways of communication with server control servers and made components more difficult to analyze.
Check Point links Cavern Manticore to Iran by a combination of technical features, infrastructure and similarities with previous operations. The group mainly attacks Israeli government agencies and IT companies. In several cases, a hacked service provider served only as an intermediate on the way to a more valuable organization.
The campaign shows that trusted remote control tools are becoming a convenient channel for hidden attacks. Cavern Manticore uses the legitimate access of IT service providers to move between organizations and mask malicious actions for conventional administration. The Cavern’s modular architecture further prevents attacks from detecting attacks in time, as hackers can quickly change the set of tools, maintaining the main platform and access to the infected infrastructure.