Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
2026-07-07T20:52:23Z•487cd1a05eb55782ea5329ceb96fdca49dc21931aeea225d2a7795edc843ae63
AI agent securityCavern ManticoreIRGCIran‑linked APTIsrael targetingLLM misuseLangGraphMOISNimbus ManticoreSQLi to RCETDS/malware distributionbrowser ransomwareclipboard hijackercommand-and-controlcrypto frauddata breachesmodular C2nation-state threatransomwaresupply-chain compromiseweekly threat intelligence
What happened
Check Point Research (June–July 2026) published multiple threat reports, led by a detailed analysis of a new modular command-and-control (C2) framework used by “Cavern Manticore,” an Iran‑MOIS–linked APT that has focused on Israeli targets (notably IT providers and government entities). The Cavern Manticore framework is modular/plugin‑based, enabling flexible deployment of capabilities for persistence, C2 communications, and likely data theft or disruptive operations. The feed also includes related high‑risk findings: a LangGraph checkpointer vulnerability chain (SQL injection leading to RCE),
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- checkpoint_research
- Record identifier
- 487cd1a05eb55782ea5329ceb96fdca49dc21931aeea225d2a7795edc843ae63
- Enrichment time
- 2026-07-07T20:52:23Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.