Feeds.Feedburner Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks
Article Content
- •Cavern Manticore uses a sophisticated modular C2 framework targeting Israeli IT and government sectors.
- •Both Cavern Manticore and OilRig are linked to Iran's Ministry of Intelligence and Security.
- •The attacks exploit legitimate software vulnerabilities to deploy trojanized components for further exploitation.
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular command-and-control (C2) framework built on a .NET foundation, utilizing various compilation formats to evade detection. The attacks often exploit vulnerabilities in legitimate software, such as SysAid, to deploy trojanized DLLs that enable further exploitation. The OilRig group has been active since 2014, previously targeting similar sectors with custom malware like the Solar and Mango backdoors. The campaigns have been characterized by their focus on reconnaissance, data theft, and lateral movement within compromised networks. Both groups are linked to Iran's Ministry of Intelligence and Security, highlighting the geopolitical implications of these cyber operations. Current assessments indicate that these threats are ongoing, with significant risks to Israeli infrastructure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (13)
Following this threat?
Track Apt34, Cavern and Altyn Asyr CJSC in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…