Iranian Spies Target Israeli IT Firms With a New Custom Toolkit Called Cavern

A hacking crew tied to Iran's intelligence ministry is running a previously unseen command-and-control framework against Israeli government bodies and their IT suppliers.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a dimly lit server room in an Israeli office building
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Check Point Research has linked a new hacking toolkit called Cavern, also written Cav3rn, to a group tied to Iran's Ministry of Intelligence and Security.
  • The campaign targets Israeli IT service providers and government departments.
  • Cavern is a modular framework: attackers load different components depending on what they want to steal or do next.
  • Check Point has not publicly named every victim, and Iran has not commented.

Israeli government offices and the IT companies that keep them running are being hit by a fresh wave of Iranian spying, according to researchers at Check Point.

The attackers are using a custom piece of software the researchers call Cavern. It's a command-and-control framework, the remote infrastructure hackers use to send orders to machines they've already compromised. Check Point says the group behind it works for Iran's Ministry of Intelligence and Security, the civilian spy agency. The campaign was first reported by The Hacker News based on Check Point's findings.

Who is being targeted and why?

IT providers and government bodies are the twin focus, and that mix isn't accidental.

IT providers hold admin credentials across dozens or hundreds of client networks. Break into one and you often inherit access to everyone they serve. That's the failure mode every managed service provider knows: one stolen set of credentials can cascade across every customer tenant they touch. Government departments are the obvious prize for an intelligence agency, emails, policy drafts, personnel files, anything that gives Tehran a clearer picture of what Israel is planning.

This is the same playbook state-linked groups have run for years. Go after the supplier, ride the trust relationship into the real target. We covered the Iranian group Handala's infrastructure claims against California Water Service in June, where investigators found no evidence of operational access despite loud public claims. Patient, quiet supply-chain targeting like this is harder to detect and harder to attribute in the moment.

What is Cavern and why does it matter?

Cavern is described as modular. Think of it as a handle with swappable heads.

One module might quietly copy files. Another could record keystrokes, or hold open a hidden tunnel so the attackers can return whenever they like. The operator loads what fits the target. That design makes the software harder for antivirus tools to flag, because each deployment looks slightly different. It also lets the group keep the core framework running for years while retiring only the burned pieces.

This isn't a smash-and-grab. It's patient espionage, and the exotic toolkit is what comes after the boring initial foothold, a phished password, an unpatched public server, a forgotten admin account.

Should ordinary people be worried?

If you're not an Israeli civil servant or working at an Israeli IT firm, this specific campaign isn't aimed at you. The goals here are intelligence collection, not financial theft.

The wider lesson holds regardless. When an IT supplier gets breached, the damage lands on their customers. If a company you deal with appears in a breach notice, treat any password reset request as suspicious and enable two-factor authentication, the second verification code sent to your phone at login, before doing anything else.

If you run a managed service provider, the operational read here is plain: assume you're on somebody's target list this quarter and audit your privileged-access accounts accordingly.

© 2026 Threat Vectr