← BACK TO FEED
TAG

iran apt1 articles

Iranian APT Cavern Manticore Is Running a Modular Hacking Framework Built With Suspicious AI Assistance

An Iran-linked APT group called Cavern Manticore, likely tied to Iran's Ministry of Intelligence and Security, has been conducting cyberattacks against Israeli government entities and IT providers using a modular C&C framework built in .NET. The framework is designed to evade analysis by using multiple compilation formats rather than traditional obfuscation, and isolates modules in separate memory domains that are wiped after use to eliminate forensic artifacts. The group demonstrates a sophisticated understanding of Israel's IT supply chains, using compromised IT providers as stepping stones to reach intended targets.

14 Jul 2026