Dormant Medium impact Espionage Checked 5d ago

Iran-linked group hits Israeli IT providers and government

Researchers say an Iran-linked hacking group known as Cavern Manticore has been quietly breaking into Israeli IT service providers since early 2026 and using that access to reach government and other high-value targets. Kaspersky and Group-IB now report the group's Cavern toolkit keeps evolving: new versions can hide their control traffic inside Google Apps Script requests, and a related module called HOLLOWGRAPH turns hacked Microsoft 365 calendars into a covert messaging channel. No destructive damage or specific victim names have been made public.

Started
Jul 4, 2026
Latest activity
Aug 17, 2026
Attributed to
Cavern Manticore (Iran-linked, suspected MOIS)Suspected
Where
Israel
Sectors
Government, Technology
Scale
Israeli government agencies and IT service providers, exact number not disclosed

Current status

Kaspersky reported on August 17, 2026 that it has been monitoring this activity cluster since December 2025 and found new Cavern C2 components, including a module that switches between direct HTTPS and a Google Apps Script relay; no credible reporting has surfaced since then.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

Kaspersky separately linked the Cavern toolkit to OilRig (APT34) with low confidence, based on shared use of Microsoft-hosted C2 infrastructure and token-refresh tricks rather than shared code or infrastructure; this does not replace the original MOIS/Cavern Manticore attribution from Check Point.

Impact

The group continues to use compromised IT providers and legitimate cloud services, including Google Apps Script and Microsoft 365 calendars, to hide its spying traffic and move into Israeli government and business networks. No data theft, outage, or destructive damage has been publicly confirmed.

What to do

Organizations that use outside IT or remote-monitoring providers, especially in Israel, should watch for unusual DNS lookups, Google Apps Script traffic, or calendar-based data transfers, and check the newest indicators researchers have published; there is no action needed for the general public.

Timeline

  1. Sep 7, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  2. Aug 17, 2026

    Kaspersky and Group-IB reported that the Cavern C2 framework used by Cavern Manticore keeps evolving, including a new module that hides control traffic behind Google Apps Script and DNS lookups, and a separate HOLLOWGRAPH module (first seen June 7, 2026) that uses hacked Microsoft 365 calendars as a covert channel; Kaspersky has monitored the cluster since December 2025 and links the toolkit to OilRig (APT34) with low confidence.

    Activethehackernews.com
  3. Aug 1, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  4. Jul 11, 2026

    SecurityOnline described continuing cyber-espionage and network infiltration activity by the suspected Iran-linked group against government networks.

    Activesecurityonline.info
  5. Jul 7, 2026

    The Hacker News and SecurityWeek reported the group, linked to Iran's Ministry of Intelligence and Security, was compromising Israeli IT service providers to reach higher-value targets.

    Activethehackernews.com
  6. Jul 4, 2026

    GBHackers reported that a newly identified group, Cavern Manticore, was deploying a modular .NET-based command-and-control framework against Israeli government and IT organizations.

    Emerginggbhackers.com

Sources

Related reports