Iran-linked Cavern Manticore malware targets Israeli government networks

Published July 4, 2026

Iran-linked attackers are using a new malware toolkit to secretly spy on Israeli government computers and spread across their networks. The malware can move between machines and gather sensitive data.

Report priority
Medium

How it works

  • Iran-linked attackers send malicious files to Israeli government computers that install a hidden malware toolkit.
  • The toolkit lets them move between machines and steal data.

What to do

If you work for an Israeli government agency or organization and recently opened a suspicious email or document, check your computer for unusual activity, like slow performance or unexpected files.

Report any suspicious emails or documents to your IT team immediately.

Technical details

An attacker sends a fake email with a malicious Word document to an Israeli government employee. When the employee opens the document, it secretly installs a malware toolkit on their computer. The toolkit then spreads to other computers in the network, letting the attackers gather sensitive information without being noticed.

A newly identified Iran-linked threat group, tracked as Cavern Manticore, is deploying a sophisticated modular command-and-control (C2) framework built on a shared .NET foundation to conduct stealthy reconnaissance and lateral movement against Israeli government and IT organizations.