NEW: Group Profiler — instant APT intel lookup. Try it →

Cleaver

G0003 Iran Espionage MITRE ATT&CK →

Also known as: Threat Group 2889 · TG-2889

Overview

Cleaver is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver. Strong circumstantial evidence suggests Cleaver is linked to Threat Group 2889 (TG-2889).

Naming & attribution

Cleaver is tracked under 3 names across the industry. It uses 5 documented ATT&CK techniques — more than 13% of the 174 groups tracked here.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Threat Group 2889Dell SecureWorks
TG-2889Dell SecureWorks
CleaverCylance

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1557.002 ARP Cache Poisoning — used by 2 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Play — 3 shared techniques (11% overlap)
  • LuminousMoth China — 3 shared techniques (10% overlap)
  • Moonstone Sleet North Korea — 3 shared techniques (9% overlap)
  • MirrorFace China — 3 shared techniques (7% overlap)
  • VOID MANTICORE Iran — 4 shared techniques (6% overlap)
  • Ke3chang China — 3 shared techniques (6% overlap)

Targets

Defense · Education · Energy · Government · Private sector · Technology

Regions

Canada · China · France · Germany · India · Israel · Kuwait · Mexico · Pakistan · Qatar · Saudi Arabia · South Korea · Turkey · United Kingdom · United States

TTPs — 5 techniques across 2 tactics

Resource Development

Credential Access

Tools & malware (4)

Net Crawler · PsExec · TinyZBot · Mimikatz

Reporting (2)