MEFILES · Edition No. 9Today's edition · Archive · RSS
Seven files · One region · Zero illusions
All Digital Front Monitor stories → The full edition of July 23, 2026 →
Censorship-in-Depth

The Quiet War: Iran's Spies Move From Defacement to the Supply Chain

A newly exposed Iranian intelligence crew burrowing into Israeli IT providers marks the shift from noisy hacktivism to persistent espionage — as hostile incidents against Israel triple.

Check Point Research disclosed "Cavern Manticore," an Iran-nexus actor tied to the Ministry of Intelligence, using a bespoke modular command-and-control framework against Israeli government and IT-provider networks. Its tradecraft is telling: abusing a legitimate IT-management update mechanism after compromise rather than a public vulnerability — the harder-to-detect end of the spectrum. Israel's cyber directorate logged roughly 4,800 hostile incidents in June 2026 against about 1,600 a year earlier. In parallel, Iran runs a "tiered" internet — a small approved whitelist restored, most global apps still blocked — a stealth model designed to look like the network is functioning.

Assessment: The move from DDoS and defacement toward quiet pre-positioning inside trusted software channels is the access that later converts into hack-and-leak or wiper operations. Iran's censorship-in-depth, reportedly built with Russian help, is the template other MENA states can adopt: information control without the reputational cost of a visible blackout.

Digital Front MonitorMEFILES tracking
4,800hostile cyber incidents against Israel in June 2026 — roughly triple a year earlier
Evidence2 cited sources · Check Point · Times of Israel
The file19 Jul: 0 stories22 Jul: 2 stories23 Jul: 1 story
Digital Front Monitor · 3 editions since 19 July 2026 · 3 stories filed · 1 in this edition