EN

Check Point: Iranian Hackers Target Israel Through Tech Providers

Sukaina Khalid

1- Check Point identified a new attack framework used by Iranian-linked Cavern Manticore against Israeli targets.
2- The company linked the group to Iran’s Ministry of Intelligence and said it has tracked it since early 2026.
3- The campaign’s risk lies in turning trusted tech providers into hidden gateways to sensitive Israeli institutions.

The latest

Iranian-linked hackers are using a new framework to breach trusted technology service providers and reach Israeli government and tech-sector targets through malware disguised as legitimate updates, according to Check Point Research.

Details

The group: Check Point linked Cavern Manticore to Iran’s Ministry of Intelligence and Security, saying it has monitored the group since early 2026.

Attack method: The report said the tool abuses remote monitoring and management, or RMM, systems to move through multiple providers before reaching the final target.

Malware capabilities: Check Point said the malware can extract files, download additional tools, test passwords and push deeper into compromised networks.

Company assessment: Check Point assessed that the group has a detailed understanding of Israel’s tech supply chains and warned of advancing Iranian cyber capabilities.

What to watch

Key signals now include any official Israeli response, possible alerts to RMM service providers, and whether the campaign expands into other sectors or targets beyond Israel.

What to read next

Is Hezbollah Losing Its Last Lifeline?

Houthis Threaten Saudi Oil Exports Through Bab al-Mandab

Khalil al-Hayya Tightens Iran’s Grip on Hamas