Dormant Medium impact Espionage Checked 4d ago

Iran-linked Cavern Manticore spies on Israeli IT and gov networks

Researchers at Check Point first exposed an Iran-linked group called Cavern Manticore breaking into Israeli IT service providers and using their trusted software tools, including SysAid, to plant a hidden backdoor on government and business networks. Kaspersky has since said it has tracked the same Cavern toolkit since December 2025 and reported on August 17, 2026 that it found a new module letting the malware hide its network traffic by switching between direct connections and Google's Apps Script service. No specific victim organizations have been named publicly and there is still no confirmed count of how many networks were hit.

Started
Jul 4, 2026
Latest activity
Aug 17, 2026
Attributed to
Cavern Manticore (Iran-linked)Likely
Where
Israel
Sectors
Government, Technology
Scale
IT service providers and government bodies in Israel, exact number not disclosed

Current status

No credible reporting or official update published after the August 17, 2026 Kaspersky disclosure of the GoogleService.dll traffic-hiding module was found.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

Kaspersky links the Cavern toolkit to Cavern Manticore, a group it ties to Iran's Ministry of Intelligence and Security with overlaps to MuddyWater and Lyceum; it also flags a low-confidence link to OilRig (APT34) based on shared technique patterns, not shared code or infrastructure.

Impact

Attackers compromised IT providers and abused their remote management and software update tools, including SysAid, to slip a hidden backdoor onto customer networks for spying and data theft. New research shows the malware's command and control system keeps evolving to better hide its traffic inside normal-looking web and email activity.

What to do

IT providers and their customers in Israel should watch for unexpected software update files and unusual outbound connections, including traffic disguised as Google Apps Script or Microsoft 365 calendar activity.

Timeline

  1. Sep 7, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  2. Aug 17, 2026

    Kaspersky reported it has monitored the Cavern C2 cluster since December 2025 and disclosed a new module, GoogleService.dll, that lets the malware pick between direct HTTPS and a Google Apps Script relay to blend in with normal traffic; it also noted a low-confidence link between Cavern and the OilRig group, and said the framework is likely to keep expanding. No new Israeli victims were named.

    Activethehackernews.com
  3. Aug 15, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  4. Jul 20, 2026

    Group-IB disclosed HOLLOWGRAPH, malware that turns compromised Microsoft 365 calendars into a hidden two-way control channel; Group-IB said it is linked with high confidence to the same Cavern toolkit but did not name Israeli victims and only noted a low-confidence tie to the separate Lyceum group.

    Dormantgroup-ib.com
  5. Jul 13, 2026

    SecurityOnline reported the campaign as an ongoing, active investigation with no named victims disclosed.

    Emergingsecurityonline.info
  6. Jul 7, 2026

    SecurityWeek reported the attackers reached targets by first compromising Israeli IT service providers.

    Emergingsecurityweek.com
  7. Jul 6, 2026

    Check Point Research published details attributing the Cavern C2 framework to an Iran-linked group with ties to MuddyWater and Lyceum.

    Emergingthehackernews.com
  8. Jul 4, 2026

    GBHackers first reported the Cavern Manticore malware framework targeting Israeli government and IT organizations.

    Emerginggbhackers.com

Sources

Related reports