Cavern Manticore

MISP
Tipo:
Unknown
Paese:
IR
Prima attivita:
Unknown
Dettagli:

Cavern Manticore is an Iran-nexus APT primarily targeting Israeli organizations in the government and IT sectors, linked to the MOIS. The group employs a modular command-and-control framework built on a shared .NET foundation, utilizing multiple compilation formats to create an anti-analysis layer. Their operations demonstrate a high operational tempo and a disciplined approach to target selection, particularly during campaigns like "Operation Epic Fury." By decoupling core infrastructure from mission-specific modules, Cavern Manticore enhances operational agility while complicating detection efforts for defenders.

Metadata
ID: 1098
Created: 27/07/2026 16:00
Updated: 08/08/2026 16:00