Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Cleaver

Also known as: Threat Group 2889, TG-2889, Operation Cleaver, Op Cleaver, Tarh Andishan, Alibaba, Cobalt Gypsy, G0003, tracked as, Goose Grass, sticky willies, APT3, Gothic Panda, UPS Team, Sandworm Team, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, TG-0110

Description

Cleaver is an Iranian‑attributed threat actor that has operated under the umbrella of Operation Cleaver for more than a decade. The group employs a hybrid toolset comprising open‑source utilities such as Mimikatz, PsExec, and Windows Credential Editor alongside custom-built backdoors, ASP.NET shells, and ARP‑poisoning scripts to establish persistence and lateral movement. Initial access frequently comes via spearphishing attachments—most notably malicious PDF files—and engineered social‑engineering vectors made possible by a self‑referenced network of fake LinkedIn profiles. Once inside, Cleaver enumerates the environment with WMI queries and file‑directory discovery, employs DLL injection and native API calls to evade detection, and dumps credentials from LSASS memory. The attacker’s modus operandi reflects a dual focus: strategic intelligence gathering on government and critical infrastructure assets while pursuing financial gain through data theft or ransomware‑style destructive encryption. Their campaigns demonstrate a persistent presence in target networks, often evading security controls by using obfuscation and frequent domain rotation.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Healthcare
Education
Manufacturing
Energy
Critical infrastructure
Non profit
Aviation
Media
Aerospace
Pharmaceutical
Hospitality
Transportation
Chemical
Information technology
Retail
Think tank
Oil gas
Mining
Gaming
Utilities
Legal services
Nuclear
Entertainment
Maritime
Construction

Targeted Countries / Regions

US
CN
RU
IR
IL
VN
JP
GB
AU
SA
PK
TW
AE
UA
SG
KR
IN
DE
BY
TR
MX
ES
PL
CA
RO
FR
NG
KP
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· 14 hours ago

Executive Summary

Cleaver, linked to Iranian actors and known as Threat Group 2889, conducts long‑term espionage and financial‑gain operations across a wide spectrum of critical sectors worldwide. The group leverages sophisticated social engineering—including fake LinkedIn profiles—and custom backdoors to gain footholds in target environments. It routinely exfiltrates data, performs credential dumping, and can deploy destructive encryption if needed.

Goals & Targeting

Cleaver seeks to infiltrate high‑value sectors—including defense, energy, telecommunications, aviation, and finance—to harvest actionable intelligence and, when profitable, exfiltrate or monetize stolen data. The actor’s emphasis on global critical infrastructures and state‑level organizations indicates a dual motivation of espionage and financial exploitation. Victims are typically nation‑state actors, utility providers, defense contractors, and large corporations that manage sensitive supply chains.

Enhanced Description

Key Capabilities

  • Custom backdoors and ASP.NET shells
  • ARP cache poisoning for lateral movement
  • DLL injection via T1055.001
  • Credential dumping with Mimikatz and Windows Credential Editor
  • Screen capture (T1113)
  • Command‑and‑control over SMB shares (T1021.002)
  • Network share discovery (T1135)
  • File/ directory enumeration (T1083)
  • Process discovery (T1057)
  • WMI querying for system discovery
  • Use of social‑engineering via fake LinkedIn profiles
  • Obfuscation/deobfuscation to evade detection
  • Data encryption for impact (T1486)

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Command & Control
Collection
Impact

ATT&CK Techniques

T1113
T1557
T1003
T1547
T1489
T1587.001
T1080
T1566.001
T1135
T1106
T1140
T1190
T1021.002
T1003.001
T1016
T1083
T1049
T1057
T1588.002
T1585.001
T1027
T1486
T1557.002
T1585
T1588
T1059.003
T1136
T1587
T1055.001
T1490

Software / Tooling

Machete
Akira
Carbanak
PoisonIvy
TinyZBot
Octopus
AppleJeus
Net Crawler
Windows Credential Editor
Mimikatz
PsExec
Custom ASP.NET shells
ARP poisoning scripts
Obfuscated PowerShell modules

Campaigns & Victims

Cleaver’s Operation Cleaver has been active since at least 2012, targeting military, energy, telecoms, aviation, and government entities globally. The campaigns feature a blend of spearphishing attachments and social‑engineering via fake LinkedIn profiles to facilitate initial compromise. Once inside, the actor deploys custom payloads and leverages open-source tools for discovery, credential dumping, and lateral movement. Persistent monitoring indicates that Cleaver frequently rotates domains (e.g., TEMP.*, .gov sites) to maintain command‑and‑control while using SMB administrative shares and WMI for lateral expansion. The group’s pattern demonstrates a sophisticated blend of espionage motives with opportunistic financial exploitation.

IOC Patterns

  • Spearphishing attachment delivering malicious PDFs
  • Fake LinkedIn profiles used for social engineering
  • Use of temporary domains (TEMP.*) in command & control
  • ASP.NET shell installation on victim servers
  • ARP cache poisoning scripts for network takeover
  • Obfuscated PowerShell or batch files to evade detection
  • SMB/Windows Admin Shares for lateral movement

Recommended Actions

  • Deploy multi‑factor authentication and least privilege controls across all accounts, particularly privileged administrative users.
  • Implement advanced phishing defenses such as attachment sandboxing and user training campaigns focusing on PDF attachments and suspicious email behavior.
  • Block known malicious domains, especially short‑lived or temporary domains that resemble official .gov sites, by using threat intelligence feeds.
  • Enable endpoint detection and response (EDR) with capabilities to detect credential dumping tools like Mimikatz, LSASS memory scans, and DLL injection.
  • Monitor network traffic for anomalous SMB sharing, WMI queries, and ARP packet spoofing – set alerts on excessive outbound SMB connections from hosts.
  • Apply regular patching to web applications (ASP.NET), operating systems, and network devices to close exploitation vectors such as T1190.

ATT&CK Techniques

Collection
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. Cylance Cleaver — Cylance. (2014, December). Operation Cleaver. Retrieved September 14, 2017.
  2. Dell Threat Group 2889 — Dell SecureWorks. (2015, October 7). Suspected Iran-Based Hacker Group Creates Network of Fake LinkedIn Profiles. Retrieved January 14, 2016.
  3. attack.mitre.org — Cited by web research for: Sandworm Team
  4. attack.mitre.org — Cited by web research for: T1587
  5. unit42.paloaltonetworks.com — Cited by web research for: T1190
  6. apt.etda.or.th — Cited by web research for: Global
  7. www.fec.gov — Cited by web research for: USA.gov

Intel Summary

30

Techniques

53

Tools

0

Campaigns

18

IOCs

0

Observed Data

10

Tactics

Tags

APT
espionage
government-sector

Details

MITRE ID
G0003
Type
Unknown
Primary Motivation
Financial gain
Country of Origin
I
Confidence
90%
Added
Jul 22, 2026
STIX ID
intrusion-set--8f5e8dc7-739d-4f5e-a8a1-a66e004d7063
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.