◇ SIGN IN
← all actors
apt

Cavern Manticore

activehigh confidence
APT / State-sponsored
Lyceum (overlap)Hexane (overlap)SiameseKitten (overlap)
Attribution
Iran-nexus actor assessed by Check Point Research to be linked to Iran's Ministry of Intelligence and Security (MOIS), with technical overlaps to the OilRig subgroup Lyceum
Origin
Iran
First seen
2026
Last active
2026
Motivation
Espionage
Confidence
high
MENA targeting
Israel
Sectors
IT / managed service providers (RMM software), government
Why it mattersState-sponsored / APT actor, high confidence, documented targeting Israel (IT / managed service providers (RMM software), government sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Cavern Manticore is an Iran-nexus, MOIS-linked APT tracked by Check Point Research since early 2026, notable for a modular .NET command-and-control framework ('Cavern') and supply-chain abuse of IT-management software against Israeli government and IT-sector targets.

History

Cavern Manticore is a recently named cluster: Check Point Research (CPR) began tracking it in early 2026 and published a detailed analysis in July 2026. CPR assesses it as an Iran-nexus actor linked to the Ministry of Intelligence and Security (MOIS), sharing technical overlaps with the OilRig subgroup Lyceum (also known as Hexane and SiameseKitten) and broader MOIS-linked activity such as MuddyWater.

The group's defining asset is a modular C2 framework called Cavern: agents and modules all built on .NET but compiled into uncommon output formats (Mixed-Mode C++/CLI and Native AOT) to frustrate reverse engineering, combined with per-module AppDomain isolation as an anti-forensics measure. Tradecraft includes DLL sideloading, LOLBins, steganography and, notably, supply-chain abuse of the SysAid IT-management update mechanism, moving from a compromised IT provider through a second-hop provider before reaching the intended victim.

MENA relevance is direct and current: CPR reports primary targeting of Israeli organizations, with a focus on IT service providers, government and defense/military sectors, using service-provider compromise to reach downstream Israeli entities.

Because this is a newly disclosed cluster, confidence in the discrete activity is medium-to-high (single primary vendor, CPR, with corroborating secondary coverage), and the MOIS/Lyceum attribution is an assessment based on tooling and TTP overlap rather than confirmed sponsorship. There is no MITRE ATT&CK group ID for this name as of this writing.

Notable campaigns

2026
Cavern C2 against Israeli IT/government
Check Point Research exposed a modular .NET C2 framework abusing SysAid supply-chain updates and multi-hop IT-provider compromise to target Israeli government, IT and defense organizations.