An Iran-linked hacking group used compromised IT service providers and a custom modular malware framework to break into organizations in Israel, especially government entities and technology suppliers. Check Point says Cavern Manticore, which it links to Iran’s Ministry of Intelligence and Security and possibly OilRig/Lyceum, abused SysAid’s software update feature to sideload a WinDirStat DLL and launch its .NET-based 'Cavern' agent, then pulled modules for file access, database and LDAP enumeration, SMB brute-force, tunneling, and lateral movement through remote monitoring tools.
Why it matters: This matters because the attackers did not just hit one victim directly; they moved through trusted IT providers to reach higher-value targets, which raises risk across connected organizations. Israeli organizations and service providers should review SysAid-related update paths, hunt for the Cavern agent and follow-on modules, and scrutinize remote management and remote desktop activity.
Ionut Arghire
2026.07.07
100% relevant
This article establishes a distinct campaign centered on Cavern Manticore’s modular C2 framework and multi-hop compromise of Israeli IT providers to reach end targets.
← Back to all stories