Iran's quiet war inside Israel's networks- 281
July 10, 2026
While Israeli and American forces struck Iranian targets from the air, a quieter campaign was already running through Israel's computer networks. An Iranian intelligence-linked hacking group, now tracked by researchers as "Cavern Manticore," spent recent months breaking into Israeli government agencies and IT companies — not by smashing through defenses, but by hijacking the very software tools those organizations trust to run their systems. The operation reveals a deliberate strategy: while the battlefield war was visible, Iran's intelligence services were using ordinary business software as a backdoor into the state itself.
The group calling itself Cavern Manticore is assessed to be linked to Iran's Ministry of Intelligence and Security, the country's main civilian spy agency. Researchers at Check Point, an Israeli cybersecurity firm, found that its tradecraft overlaps with two other known Iranian operations, MuddyWater and Lyceum — the latter itself a branch of a larger Iranian group called OilRig. In plain terms, this isn't a lone hacking crew; it's one thread in a wider fabric of Iranian state cyber-espionage units that appear to share tools, techniques, and targets.

What makes the campaign notable isn't just who is behind it, but how it gets in. Rather than attacking a target company head-on, Cavern Manticore goes after the IT service providers and remote-management software that company relies on — the equivalent of breaking into a building's maintenance contractor instead of the building itself. Once inside, the attackers abuse a legitimate update feature in SysAid, a widely used IT-helpdesk software, to slip in a piece of disguised malicious code. From there, they can move from one client of that IT provider to another, treating the trusted relationship between vendor and customer as a tunnel into multiple victims at once. In some cases, they even used built-in remote-desktop and remote-printing features — tools meant for legitimate technical support — to quietly copy data out of networks that had otherwise locked down more obvious routes like copy-paste or file transfers.

Once established, the group runs its operations through a purpose-built remote-control system it calls "Cavern." Its defining trait is not raw sophistication but stealth-by-design: the system is built in an unusual, fragmented way specifically to frustrate the analysts who would try to take it apart. Each piece of the toolkit operates in its own sealed compartment, so that even if defenders catch and dissect one component, they can't use it to expose the rest of the network. Check Point noted that most samples of this toolkit went almost entirely undetected by standard antivirus scanning — a sign of how much engineering effort went into evading detection rather than simply attacking harder. Investigators were also able to trace the command server behind the operation to a domain registered through Fars Data, an Iranian hosting company, reinforcing the Iranian government link.
This was not an isolated break-in. Around the same period, a related Iranian group, MuddyWater, ran a much broader reconnaissance sweep, probing more than 12,000 internet-connected systems worldwide by exploiting known software flaws. That sweep didn't stay passive: it escalated into password-guessing attacks on email systems and ultimately confirmed theft of sensitive data from aviation, energy, and government organizations in Egypt, Israel, and the United Arab Emirates. Seen together, Cavern Manticore's precision targeting of Israeli institutions and MuddyWater's wide-net regional sweep look less like two separate incidents and more like coordinated phases of the same intelligence push — one hitting hard at Israel specifically, the other casting widely across allied and neighboring states during the same window of military tension.
The strategic takeaway for anyone watching this space is straightforward: Iran's intelligence services are treating the software supply chain — the IT vendors, update systems, and remote-support tools that every modern institution depends on — as a soft entry point into hardened targets, and they are timing this activity to coincide with periods of open military confrontation. Defending against this kind of campaign means paying attention not just to one's own security, but to the security posture of every outside vendor with privileged remote access into the network.
