MEFILES · Edition No. 9Today's edition · Archive · RSS
Seven files · One region · Zero illusions
Digital Front Monitor The full edition of July 23, 2026 →
Censorship-in-Depth

The Quiet War: Iran's Spies Move From Defacement to the Supply Chain

A newly exposed Iranian intelligence crew burrowing into Israeli IT providers marks the shift from noisy hacktivism to persistent espionage — as hostile incidents against Israel triple.

Check Point Research disclosed "Cavern Manticore," an Iran-nexus actor tied to the Ministry of Intelligence, using a bespoke modular command-and-control framework against Israeli government and IT-provider networks. Its tradecraft is telling: abusing a legitimate IT-management update mechanism after compromise rather than a public vulnerability — the harder-to-detect end of the spectrum. Israel's cyber directorate logged roughly 4,800 hostile incidents in June 2026 against about 1,600 a year earlier. In parallel, Iran runs a "tiered" internet — a small approved whitelist restored, most global apps still blocked — a stealth model designed to look like the network is functioning.

Assessment: The move from DDoS and defacement toward quiet pre-positioning inside trusted software channels is the access that later converts into hack-and-leak or wiper operations. Iran's censorship-in-depth, reportedly built with Russian help, is the template other MENA states can adopt: information control without the reputational cost of a visible blackout.