← Back to feed
Threat Actors & CampaignsEmerging1 sourceJul 6, 2026 · 12:25via Check Point Research

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

Brief

Note: SysAid was not compromised, and no SysAid vulnerability was involved. The attacker had already gained access to the victim environment and abused a legitimate software-deployment feature to deploy malware onto another machine within it.

Key Points

  • Check Point Research (CPR) tracks ‘ Cavern Manticore ’ as an Iran-nexus threat actor operating against Israeli targets , with a focus on the government and IT sectors.
  • Cavern Manticore shares technical overlaps with other Iranian MOIS (Ministry of Intelligence and Security)-linked threat actors, including  MuddyWater  and  Lyceum .
  • CPR observed a modular C2 framework in the wild, with all samples built on top of .NET but compiled into different output formats. These components are used as  Cavern agent  and  Cavern modules .
Read more on Check Point Research