Iran-linked Cavern Manticore spies on Israeli IT and gov networks
Researchers at Check Point first exposed an Iran-linked group called Cavern Manticore breaking into Israeli IT service providers and using their trusted software tools, including SysAid, to plant a hidden backdoor on government and business networks. Kaspersky has since said it has tracked the same Cavern toolkit since December 2025 and reported on August 17, 2026 that it found a new module letting the malware hide its network traffic by switching between direct connections and Google's Apps Script service. No specific victim organizations have been named publicly and there is still no confirmed count of how many networks were hit.
- Started
- Jul 4, 2026
- Latest activity
- Aug 17, 2026
- Attributed to
- Cavern Manticore (Iran-linked)Likely
- Where
- Israel
- Sectors
- Government, Technology
- Scale
- IT service providers and government bodies in Israel, exact number not disclosed
Current status
No credible reporting or official update published after the August 17, 2026 Kaspersky disclosure of the GoogleService.dll traffic-hiding module was found.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Who is behind it
Kaspersky links the Cavern toolkit to Cavern Manticore, a group it ties to Iran's Ministry of Intelligence and Security with overlaps to MuddyWater and Lyceum; it also flags a low-confidence link to OilRig (APT34) based on shared technique patterns, not shared code or infrastructure.
Impact
Attackers compromised IT providers and abused their remote management and software update tools, including SysAid, to slip a hidden backdoor onto customer networks for spying and data theft. New research shows the malware's command and control system keeps evolving to better hide its traffic inside normal-looking web and email activity.
What to do
IT providers and their customers in Israel should watch for unexpected software update files and unusual outbound connections, including traffic disguised as Google Apps Script or Microsoft 365 calendar activity.
Timeline
-
Sep 7, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Aug 17, 2026
Kaspersky reported it has monitored the Cavern C2 cluster since December 2025 and disclosed a new module, GoogleService.dll, that lets the malware pick between direct HTTPS and a Google Apps Script relay to blend in with normal traffic; it also noted a low-confidence link between Cavern and the OilRig group, and said the framework is likely to keep expanding. No new Israeli victims were named.
Activethehackernews.com -
Aug 15, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Jul 20, 2026
Group-IB disclosed HOLLOWGRAPH, malware that turns compromised Microsoft 365 calendars into a hidden two-way control channel; Group-IB said it is linked with high confidence to the same Cavern toolkit but did not name Israeli victims and only noted a low-confidence tie to the separate Lyceum group.
Dormantgroup-ib.com -
Jul 13, 2026
SecurityOnline reported the campaign as an ongoing, active investigation with no named victims disclosed.
Emergingsecurityonline.info -
Jul 7, 2026
SecurityWeek reported the attackers reached targets by first compromising Israeli IT service providers.
Emergingsecurityweek.com -
Jul 6, 2026
Check Point Research published details attributing the Cavern C2 framework to an Iran-linked group with ties to MuddyWater and Lyceum.
Emergingthehackernews.com -
Jul 4, 2026
GBHackers first reported the Cavern Manticore malware framework targeting Israeli government and IT organizations.
Emerginggbhackers.com
Sources
- Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations TheHackerNews Jul 6, 2026
- Iran-linked attackers target Israeli firms via IT providers SecurityWeek Jul 7, 2026
- Cavern Manticore APT targets government networks SecurityOnline Jul 13, 2026
- Iran-linked Cavern Manticore malware targets Israeli government networks GBHackers Jul 4, 2026
- HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels Group-IB Jul 20, 2026
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 The Hacker News Jul 20, 2026
- Iran Deploys NightLedger Backdoor and WebSocket Relays Across Six Nations Tech Times Jul 29, 2026
- Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic The Hacker News Aug 17, 2026
Related reports
- Microsoft 365 calendar malware steals data Jul 20, 2026
- HOLLOWGRAPH malware hides in Microsoft 365 calendars Jul 17, 2026
- Microsoft 365 calendar events hide spyware commands Jul 17, 2026
- Outlook malware hides commands in fake 2050 calendar events Jul 13, 2026
- Iran-linked attackers target Israeli firms with Cavern malware Jul 7, 2026
- HollowGraph malware hides in Microsoft 365 calendar invites Jul 5, 2026
- Iran-linked Cavern Manticore malware targets Israeli government networks Jul 4, 2026