The latest
Iranian-linked hackers are using a new framework to breach trusted technology service providers and reach Israeli government and tech-sector targets through malware disguised as legitimate updates, according to Check Point Research.
Details
• The group: Check Point linked Cavern Manticore to Iran’s Ministry of Intelligence and Security, saying it has monitored the group since early 2026.
• Attack method: The report said the tool abuses remote monitoring and management, or RMM, systems to move through multiple providers before reaching the final target.
• Malware capabilities: Check Point said the malware can extract files, download additional tools, test passwords and push deeper into compromised networks.
• Company assessment: Check Point assessed that the group has a detailed understanding of Israel’s tech supply chains and warned of advancing Iranian cyber capabilities.
What to watch
Key signals now include any official Israeli response, possible alerts to RMM service providers, and whether the campaign expands into other sectors or targets beyond Israel.