Threadlinqs IntelligenceStart free

Threat actorIranTracked since 2026-07

Cavern Manticore

As of 2026-08-17, Cavern Manticore is a Iran-nexus threat actor tracked by Threadlinqs Intelligence across 7 threats spanning malware, apt. ATT&CK coverage spans 131 techniques across 13 tactics in 7 of 7 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel), T1071.001 (Web Protocols).

Tracked threats
77 high
First seen
2026-07-06
Last seen
2026-08-17
ATT&CK techniques
131across 7 of 7 threats
Related CVEs
0None referenced
Attribution
IranNation or origin
Nation: Iran · 7 tracked threat(s) · Categories: MALWARE, APT

Activity timeline

Cavern Manticore appears in 7 tracked threats between and ; the busiest month was 2026-07 with 6 reports.

ATT&CK techniques observed

131 techniques observed across 7 of 7 tracked threats · Command and Control (24), Discovery (22), Stealth (formerly Defense Evasion) (15), Collection (13), Lateral Movement (12), Credential Access (9)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 7 of 7 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 6 of 7 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 6 of 7 tracked threats
  • T1135 Network Share Discovery — Discoveryobserved in 6 of 7 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 6 of 7 tracked threats
  • T1005 Data from Local System — Collectionobserved in 5 of 7 tracked threats
  • T1046 Network Service Discovery — Discoveryobserved in 5 of 7 tracked threats
  • T1071.004 Application Layer Protocol: DNS — Command and Controlobserved in 5 of 7 tracked threats
  • T1199 Trusted Relationship — Initial Accessobserved in 5 of 7 tracked threats
  • T1574.001 DLL — Stealth (formerly Defense Evasion)observed in 5 of 7 tracked threats
  • T1008 Fallback Channels — Command and Controlobserved in 4 of 7 tracked threats
  • T1018 Remote System Discovery — Discoveryobserved in 4 of 7 tracked threats
  • T1020 Automated Exfiltration — Exfiltrationobserved in 4 of 7 tracked threats
  • T1021.002 SMB/Windows Admin Shares — Lateral Movementobserved in 4 of 7 tracked threats
  • T1087.002 Account Discovery: Domain Account — Discoveryobserved in 4 of 7 tracked threats

Tracked threats