Iran-linked group hits Israeli IT providers and government
Researchers say an Iran-linked hacking group known as Cavern Manticore has been quietly breaking into Israeli IT service providers since early 2026 and using that access to reach government and other high-value targets. Kaspersky and Group-IB now report the group's Cavern toolkit keeps evolving: new versions can hide their control traffic inside Google Apps Script requests, and a related module called HOLLOWGRAPH turns hacked Microsoft 365 calendars into a covert messaging channel. No destructive damage or specific victim names have been made public.
- Started
- Jul 4, 2026
- Latest activity
- Aug 17, 2026
- Attributed to
- Cavern Manticore (Iran-linked, suspected MOIS)Suspected
- Where
- Israel
- Sectors
- Government, Technology
- Scale
- Israeli government agencies and IT service providers, exact number not disclosed
Current status
Kaspersky reported on August 17, 2026 that it has been monitoring this activity cluster since December 2025 and found new Cavern C2 components, including a module that switches between direct HTTPS and a Google Apps Script relay; no credible reporting has surfaced since then.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Who is behind it
Kaspersky separately linked the Cavern toolkit to OilRig (APT34) with low confidence, based on shared use of Microsoft-hosted C2 infrastructure and token-refresh tricks rather than shared code or infrastructure; this does not replace the original MOIS/Cavern Manticore attribution from Check Point.
Impact
The group continues to use compromised IT providers and legitimate cloud services, including Google Apps Script and Microsoft 365 calendars, to hide its spying traffic and move into Israeli government and business networks. No data theft, outage, or destructive damage has been publicly confirmed.
What to do
Organizations that use outside IT or remote-monitoring providers, especially in Israel, should watch for unusual DNS lookups, Google Apps Script traffic, or calendar-based data transfers, and check the newest indicators researchers have published; there is no action needed for the general public.
Timeline
-
Sep 7, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Aug 17, 2026
Kaspersky and Group-IB reported that the Cavern C2 framework used by Cavern Manticore keeps evolving, including a new module that hides control traffic behind Google Apps Script and DNS lookups, and a separate HOLLOWGRAPH module (first seen June 7, 2026) that uses hacked Microsoft 365 calendars as a covert channel; Kaspersky has monitored the cluster since December 2025 and links the toolkit to OilRig (APT34) with low confidence.
Activethehackernews.com -
Aug 1, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Jul 11, 2026
SecurityOnline described continuing cyber-espionage and network infiltration activity by the suspected Iran-linked group against government networks.
Activesecurityonline.info -
Jul 7, 2026
The Hacker News and SecurityWeek reported the group, linked to Iran's Ministry of Intelligence and Security, was compromising Israeli IT service providers to reach higher-value targets.
Activethehackernews.com -
Jul 4, 2026
GBHackers reported that a newly identified group, Cavern Manticore, was deploying a modular .NET-based command-and-control framework against Israeli government and IT organizations.
Emerginggbhackers.com
Sources
- Cavern Manticore: Exposing Iran-Linked Modular C2 Framework Check Point Research Jul 1, 2026
- Iran-linked attackers target Israeli firms with Cavern malware TheHackerNews Jul 7, 2026
- Iran-linked attackers target Israeli firms via IT providers SecurityWeek Jul 7, 2026
- Iran-linked Cavern Manticore malware targets Israeli government networks GBHackers Jul 4, 2026
- Cavern Manticore APT targets government networks SecurityOnline Jul 11, 2026
- Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic The Hacker News Aug 17, 2026