Cavern Manticore is an Iran-nexus, MOIS-linked APT tracked by Check Point Research since early 2026, notable for a modular .NET command-and-control framework ('Cavern') and supply-chain abuse of IT-management software against Israeli government and IT-sector targets.
Cavern Manticore is a recently named cluster: Check Point Research (CPR) began tracking it in early 2026 and published a detailed analysis in July 2026. CPR assesses it as an Iran-nexus actor linked to the Ministry of Intelligence and Security (MOIS), sharing technical overlaps with the OilRig subgroup Lyceum (also known as Hexane and SiameseKitten) and broader MOIS-linked activity such as MuddyWater.
The group's defining asset is a modular C2 framework called Cavern: agents and modules all built on .NET but compiled into uncommon output formats (Mixed-Mode C++/CLI and Native AOT) to frustrate reverse engineering, combined with per-module AppDomain isolation as an anti-forensics measure. Tradecraft includes DLL sideloading, LOLBins, steganography and, notably, supply-chain abuse of the SysAid IT-management update mechanism, moving from a compromised IT provider through a second-hop provider before reaching the intended victim.
MENA relevance is direct and current: CPR reports primary targeting of Israeli organizations, with a focus on IT service providers, government and defense/military sectors, using service-provider compromise to reach downstream Israeli entities.
Because this is a newly disclosed cluster, confidence in the discrete activity is medium-to-high (single primary vendor, CPR, with corroborating secondary coverage), and the MOIS/Lyceum attribution is an assessment based on tooling and TTP overlap rather than confirmed sponsorship. There is no MITRE ATT&CK group ID for this name as of this writing.
OSINT feed items linking this actor. Latest Intel →