Also known as: Threat Group 2889, TG-2889, Operation Cleaver, Op Cleaver, Tarh Andishan, Alibaba, Cobalt Gypsy, G0003, tracked as, Goose Grass, sticky willies, APT3, Gothic Panda, UPS Team, Sandworm Team, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, TG-0110
Cleaver is an Iranian‑attributed threat actor that has operated under the umbrella of Operation Cleaver for more than a decade. The group employs a hybrid toolset comprising open‑source utilities such as Mimikatz, PsExec, and Windows Credential Editor alongside custom-built backdoors, ASP.NET shells, and ARP‑poisoning scripts to establish persistence and lateral movement. Initial access frequently comes via spearphishing attachments—most notably malicious PDF files—and engineered social‑engineering vectors made possible by a self‑referenced network of fake LinkedIn profiles. Once inside, Cleaver enumerates the environment with WMI queries and file‑directory discovery, employs DLL injection and native API calls to evade detection, and dumps credentials from LSASS memory. The attacker’s modus operandi reflects a dual focus: strategic intelligence gathering on government and critical infrastructure assets while pursuing financial gain through data theft or ransomware‑style destructive encryption. Their campaigns demonstrate a persistent presence in target networks, often evading security controls by using obfuscation and frequent domain rotation.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Cleaver, linked to Iranian actors and known as Threat Group 2889, conducts long‑term espionage and financial‑gain operations across a wide spectrum of critical sectors worldwide. The group leverages sophisticated social engineering—including fake LinkedIn profiles—and custom backdoors to gain footholds in target environments. It routinely exfiltrates data, performs credential dumping, and can deploy destructive encryption if needed.
Goals & Targeting
Cleaver seeks to infiltrate high‑value sectors—including defense, energy, telecommunications, aviation, and finance—to harvest actionable intelligence and, when profitable, exfiltrate or monetize stolen data. The actor’s emphasis on global critical infrastructures and state‑level organizations indicates a dual motivation of espionage and financial exploitation. Victims are typically nation‑state actors, utility providers, defense contractors, and large corporations that manage sensitive supply chains.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Cleaver’s Operation Cleaver has been active since at least 2012, targeting military, energy, telecoms, aviation, and government entities globally. The campaigns feature a blend of spearphishing attachments and social‑engineering via fake LinkedIn profiles to facilitate initial compromise. Once inside, the actor deploys custom payloads and leverages open-source tools for discovery, credential dumping, and lateral movement. Persistent monitoring indicates that Cleaver frequently rotates domains (e.g., TEMP.*, .gov sites) to maintain command‑and‑control while using SMB administrative shares and WMI for lateral expansion. The group’s pattern demonstrates a sophisticated blend of espionage motives with opportunistic financial exploitation.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
30
Techniques
53
Tools
0
Campaigns
18
IOCs
0
Observed Data
10
Tactics