INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Iran-Nexus Hacking Group Targets Israel Government and IT Sectors

| 2026-07-06 12:25 CRITICAL HIGH
Executive Summary AI-generated
The new Iran-Nexus hacking group, tracked as 'Cavern Manticore,' has been linked to the Iranian government and is targeting Israeli government and IT organizations. This threat group shares technical overlaps with other Iranian adversaries like MuddyWater and Lyceum, two groups attributed to Iran's Ministry of Intelligence and Security. The Cavern Manticore group gained access to defense and government sectors during a US military campaign, demonstrating operational tempo and disciplined target selection. A new cyber threat has emerged linked to the Iranian government, with Check Point Research reporting that Israeli organizations have been targeted since early 2026.
Technical Mitigations AI-generated
* Implement a secure remote monitoring and management (RMM) software policy to prevent exploitation of existing vulnerabilities, such as the use of .NET compilation formats like .NET Framework, .NET Mixed-Mode C++/CLI, and .NET Native AOT. * Regularly update and patch all RMM software to ensure that any known vulnerabilities are addressed before they can be exploited by attackers using this type of malware. * Use a secure communication protocol, such as HTTPS or SFTP, when communicating with the attacker-controlled IIS server hosting the C2 module (cac.aspx) to prevent eavesdropping and tampering. * Implement AppDomain isolation on all Windows systems to prevent defenders from recovering full capabilities from a compromised host by using per-module AppDomain isolation in the Cavern Manticore framework. * Use a secure file system, such as encrypted volumes or network-attached storage (NAS), when storing sensitive data on the compromised environment to prevent unauthorized access and exfiltration of data.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation Epic FuryOperation Epic Fury MuddyWaterMuddyWaterOilRigOilRig
Target & Sectors
NORTH_AMERICA NORTH_AMERICA defensedefense governmentgovernment
Incident Timeline
‎2026/07/06
The threat actors used a modular C2 framework to target the same project, which was refactored and split across separate modules for improved hardening.
‎July 6
Threat actors used Iranian government-linked modular C2 framework to target organizations in the defense and government sectors.
industry Government
target_region United States
industry Defense
campaign Operation Epic Fury
‎2026/07/06
Cavern Manticore exploited an older Cav3rn agent and the older mhm.dll variant, carried as configuration by the older cav3rn agent.
organisation Cavern Manticore
threat_actor OilRig
threat_actor MuddyWater
organisation Conclusion Cavern Manticore
organisation RMM
organisation Cavern Manticore’s
organisation XOR
organisation LDAP / Active Directory
organisation SOCKS5 / WebSocket
organisation AppDomain
organisation LDAP Module
organisation Command
data_breach 312 FILE_FOLDER_LIST
data_breach 313 SEARCH_FILE
data_breach 314 SEARCH_FILE
data_breach 402 SEARCH_FILE
organisation DNS
organisation SOCKS5 / WebSocket Tunnel
organisation DPAPI
organisation db.dll
data_breach 5.2 SQL Database Browser
organisation SMB
organisation Tunnel Module
organisation IL + Native
organisation Communication Module
organisation HTTPS/WebSocket
data_breach 5.1 File Manager
financial 314 directory block
organisation API
organisation JPEG
infrastructure 3.6
infrastructure 3.7
organisation Command Action
organisation Reconnect WebSocket
organisation Anti-Forensics Newer
infrastructure 002 GZip+Base64
infrastructure 5.5
organisation The Communication Module
data_breach 5.5 MB
organisation HTTPS
organisation ASP.NET
organisation NET_PORT_SCN
organisation DLL
infrastructure Windows
infrastructure 5.0
infrastructure 10.0
infrastructure 537.36
infrastructure 146.0.0
organisation Microsoft Edge
organisation Win64
organisation KHTML
infrastructure 3.2
infrastructure 3.8
organisation Working-dir
organisation Debug Default
organisation Mutex
organisation Cvn.cfg
infrastructure 3.5
organisation WebSocket
organisation Content-Disposition
data_breach 21 byte
organisation Attribution During
organisation VirusTotal
organisation Technical Overlaps with Other Iranian Adversaries
financial 702 SRV_RESET
organisation P/Invoke Target
organisation GetMembers
organisation SysAid
organisation CPR
organisation Cavern
organisation Remote Monitoring and Management
organisation Cavern Modules Evade
organisation Anti-Analysis
organisation PE
organisation NativeAOT
organisation Washi
organisation PDB
organisation Custom AppDomain Isolation
infrastructure 3.3 Custom AppDomain Isolation
organisation Assembly
organisation IntPtr
organisation 0x0074
organisation POST
organisation UA
organisation Post-Exploitation Modules
organisation IOC
organisation CryptDecrypt
organisation ProtectedData
organisation SQL
organisation DN
organisation TLS
organisation WSS
organisation LINQ
organisation hospitalinstallation[.]com
organisation Fars Data
organisation Protections Check Point Threat Emulation
data_breach 3 MB binary
financial 1 tool
financial 20 export ordinal
financial 601 Cav3rn
infrastructure 21 loaded API descriptors
organisation Check Point
‎early 2026
Threat actors used a modular command-and-control framework from Cavern Manticore to target Israeli government and IT organizations.
source_region Iran, Islamic Republic of
industry Government
attribution Check Point Research
source_region Israel
attribution APT
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎3.2
Software Version
Metrics
infrastructure
‎3.5
Software Version
Metrics
infrastructure
‎3.6
Software Version
Metrics
infrastructure
‎3.7
Software Version
Metrics
infrastructure
2
Gzip+Base64
Metrics
infrastructure
‎3.8
Software Version
Metrics
infrastructure
‎5.5
Software Version
Metrics
data_breach
6
Mb
Metrics
infrastructure
‎5.0
Software Version
Metrics
infrastructure
‎10.0
Software Version
Metrics
infrastructure
‎537.36
Software Version
Metrics
infrastructure
‎146.0.0
Software Version
Metrics
data_breach
312
File_Folder_List
Metrics
data_breach
313
Search_File
Metrics
data_breach
314
Search_File
Metrics
data_breach
402
Search_File
Metrics
data_breach
21
Byte
Metrics
data_breach
5
File Manager
Metrics
financial
314
Directory Block
Metrics
data_breach
5
Sql Database Browser
Metrics
infrastructure
3
Custom Appdomain Isolation
Metrics
data_breach
3
Mb Binary
Metrics
financial
1
Tool
Metrics
financial
20
Export Ordinal
Metrics
financial
601
Cav3Rn
Metrics
financial
702
Srv_Reset
Metrics
infrastructure
21
Loaded Api Descriptors
Intelligence Sources
Infosecurity-Magazine 2026-07-06