Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

2026-07-07T20:52:23Z487cd1a05eb55782ea5329ceb96fdca49dc21931aeea225d2a7795edc843ae63
AI agent securityCavern ManticoreIRGCIran‑linked APTIsrael targetingLLM misuseLangGraphMOISNimbus ManticoreSQLi to RCETDS/malware distributionbrowser ransomwareclipboard hijackercommand-and-controlcrypto frauddata breachesmodular C2nation-state threatransomwaresupply-chain compromiseweekly threat intelligence

What happened

Check Point Research (June–July 2026) published multiple threat reports, led by a detailed analysis of a new modular command-and-control (C2) framework used by “Cavern Manticore,” an Iran‑MOIS–linked APT that has focused on Israeli targets (notably IT providers and government entities). The Cavern Manticore framework is modular/plugin‑based, enabling flexible deployment of capabilities for persistence, C2 communications, and likely data theft or disruptive operations. The feed also includes related high‑risk findings: a LangGraph checkpointer vulnerability chain (SQL injection leading to RCE),

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
checkpoint_research
Record identifier
487cd1a05eb55782ea5329ceb96fdca49dc21931aeea225d2a7795edc843ae63
Enrichment time
2026-07-07T20:52:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.