Iran-linked attackers target Israeli firms with Cavern malware

Published July 7, 2026

Iran-linked attackers use a new spy tool called Cavern to break into Israeli companies. It steals data and lets attackers control infected computers.

Report priority
Medium

How it works

Attackers send a fake email or infected file to trick employees into opening it, which installs Cavern malware on their work computer.

What to do

Check if your work computer has been infected by looking for unusual network activity or unexpected files in your downloads folder.

Update your antivirus software and report any suspicious emails or files to your IT team immediately.

Technical details

An Israeli employee clicks a link in a fake invoice email. The link downloads a hidden program that secretly connects to a remote server. The attackers then use that link to spy on the employee's work files and send stolen data back to Iran.

Check Point Research tracks the operators as Cavern Manticore, a cluster overlapping with MuddyWater and Lyceum (a OilRig subgroup). The Cavern framework mixes.NET Framework, Mixed-Mode C++/CLI, and Native AOT compiled components specifically to slow down reverse engineers, and isolates each module in its own AppDomain to limit forensic traces. The main agent, uxtheme.dll, is side-loaded via a trojanized SysAid update chain and talks to over HTTPS or WebSocket, then pulls down modules for file operations, SQL database abuse, Active Directory and network reconnaissance, and SOCKS5 tunneling.