NEW: Group Profiler — instant APT intel lookup. Try it →

← threatfilter.dev / all groups / Cleaver

Cleaver

G0003 Iran Espionage MITRE ATT&CK →

Also known as: Threat Group 2889 · TG-2889

Overview

Cleaver is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver. Strong circumstantial evidence suggests Cleaver is linked to Threat Group 2889 (TG-2889).

Targets

Defense · Education · Energy · Government · Private sector · Technology

Regions

Canada · China · France · Germany · India · Israel · Kuwait · Mexico · Pakistan · Qatar · Saudi Arabia · South Korea · Turkey · United Kingdom · United States

TTPs — 5 techniques across 2 tactics

Resource Development

Credential Access

Tools & malware (4)

Net Crawler · PsExec · TinyZBot · Mimikatz

Reporting (2)