Cavern Manticore
- Origin
- IR
- Profile updated
- 2026-07-28 03:00:02
Context
Cavern Manticore is an Iran-nexus APT primarily targeting Israeli organizations in the government and IT sectors, linked to the MOIS. The group employs a modular command-and-control framework built on a shared .NET foundation, utilizing multiple compilation formats to create an anti-analysis layer. Their operations demonstrate a high operational tempo and a disciplined approach to target selection, particularly during campaigns like "Operation Epic Fury." By decoupling core infrastructure from mission-specific modules, Cavern Manticore enhances operational agility while complicating detection efforts for defenders.
Reports & references
- research.checkpoint.com — Cavern Manticore Exposing Iran Linked Modular C2 Framework (report)