Cleaver
Also known as: Threat Group 2889 · TG-2889
Overview
Cleaver is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver. Strong circumstantial evidence suggests Cleaver is linked to Threat Group 2889 (TG-2889).
Naming & attribution
Cleaver is tracked under 3 names across the industry. It uses 5 documented ATT&CK techniques — more than 13% of the 174 groups tracked here.
| Name | First reported by |
|---|---|
| Threat Group 2889 | Dell SecureWorks |
| TG-2889 | Dell SecureWorks |
| Cleaver | Cylance |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1557.002ARP Cache Poisoning — used by 2 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Play — 3 shared techniques (11% overlap)
- LuminousMoth China — 3 shared techniques (10% overlap)
- Moonstone Sleet North Korea — 3 shared techniques (9% overlap)
- MirrorFace China — 3 shared techniques (7% overlap)
- VOID MANTICORE Iran — 4 shared techniques (6% overlap)
- Ke3chang China — 3 shared techniques (6% overlap)
Targets
Defense · Education · Energy · Government · Private sector · Technology
Regions
Canada · China · France · Germany · India · Israel · Kuwait · Mexico · Pakistan · Qatar · Saudi Arabia · South Korea · Turkey · United Kingdom · United States
TTPs — 5 techniques across 2 tactics
Resource Development
-
T1585.001Social Media Accounts -
T1587.001Malware -
T1588.002Tool
Credential Access
-
T1003.001LSASS Memory -
T1557.002ARP Cache Poisoning
Tools & malware (4)
Net Crawler · PsExec · TinyZBot · Mimikatz
Reporting (2)
- Suspected Iran-Based Hacker Group Creates Network of Fake LinkedIn Profiles — Dell SecureWorks
- Operation Cleaver — Cylance