Iranian APT Escalation: Massive Surge in Cyber Operations Against Israeli Infrastructure
Following a U.S.-Israeli military offensive, Iranian-linked Advanced Persistent Threat (APT) actors have executed a massive escalation in cyber warfare, resulting in a 300% increase in hostile incidents. Intelligence indicates 4,800 recorded attacks in June 2026, compared to approximately 1,600 in June 2025. This campaign is characterized by the tactical unification of various Iranian hacking groups utilizing shared infrastructure and coordinated Tactics, Techniques, and Procedures (TTPs). Targeting has expanded from specialized government networks to include critical infrastructure and Small and Medium-sized Businesses (SMBs) to maximize systemic disruption and social impact.
Cavern Manticore Exploiting SysAid via Modular Cavern C2 Framework
Iranian state-sponsored threat actor Cavern Manticore, linked to the Ministry of Intelligence and Security (MOIS), has executed a targeted campaign against Israeli government agencies and IT service providers. The intrusion leverages a supply chain compromise of the SysAid software platform to achieve initial access. Following exploitation, the actor deploys the "Cavern" (Cav3rn) framework, a modular and highly adaptable command-and-control (C2) architecture designed for deep reconnaissance and data exfiltration. This campaign demonstrates advanced tactical continuity with established Iranian APTs, specifically MuddyWater and Lyceum, utilizing specialized modular tasking to maintain persistence and navigate high-value environments.
Iran-Linked MuddyWater Actors Compromising Rockwell Automation PLCs in U.S. Critical Infrastructure
Iranian state-sponsored group MuddyWater, affiliated with the Ministry of Intelligence and Security, is actively targeting U.S. critical infrastructure by exploiting internet-exposed Rockwell Automation Programmable Logic Controllers (PLCs). The attackers leverage these exposed OT interfaces to deploy SSH backdoors for persistent access. Once established, they manipulate SCADA display data to deceive industrial operators, masking the actual state of physical processes within the water, energy, and government sectors. This activity, detailed in CISA/FBI Joint Advisory AA26-097A, represents a direct effort to facilitate operational disruptions through the manipulation of Industrial Control Systems (ICS).