Cleaver
MITRE ATT&CK: G0003 View on attack.mitre.org
Aliases: Threat Group 2889, TG-2889, Operation Cleaver, Op Cleaver, Tarh Andishan, Alibaba, Cobalt Gypsy, Cleaver
- First seen
- 2012-01-01 00:00:00
- Origin
- IR
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Last IoC activity
- 2026-07-22 04:04:45
- Profile updated
- 2026-07-07 12:31:33
Targeted industries: defense-and-aerospace energy-and-utilities government-and-public-sector transportation-and-logistics
Targeted regions: country_code:us country_code:sa country_code:qa country_code:ae country_code:kr
Context
Cleaver is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver. Strong circumstantial evidence suggests Cleaver is linked to Threat Group 2889 (TG-2889).
Detection coverage
- 7 YARA rules
- 89 Sigma rules
Malware & tools used
- LSASS Memory (attack-pattern)
- ARP Cache Poisoning (attack-pattern)
- Tool (attack-pattern)
- Malware (attack-pattern)
- Social Media Accounts (attack-pattern)
- Mimikatz (malware)
- TinyZBot (malware)
- Net Crawler (malware)
- PsExec (malware)
Related threat objects
- CHRYSENE (threat-actor)
- Hazel Sandstorm (threat-actor)
- Magic Hound (threat-actor)
- Cutting Kitten (threat-actor)
- Clever Kitten (threat-actor)
- Rocket Kitten (threat-actor)
- Charming Kitten (threat-actor)
Reports & references
- Microsoft — New Steps To Protect Customers From Hacking (report)
- Trend Micro — Operation Woolen Goldfish When Kittens Go Phishing (report)
- blog.checkpoint.com — Rocket Kitten Report (report)
- secureworks.com — The Curious Case Of Mia Ash (report)
- cfr.org — Operation Cleaver (report)
- secureworks.com — Suspected Iran Based Hacker Group Creates Network Of Fake Linkedin Profiles (report)
- secureworks.com — Iranian Pupyrat Bites Middle Eastern Organizations (report)
- trendmicro.de — Wp The Spy Kittens Are Back (report)
- MITRE ATT&CK — G0003 (report)
- xorl.wordpress.com — Iran Cyber Operations Groups (report)
- secureworks.com — Suspected Iran Based Hacker Group Creates Network Of Fake Linkedin Profiles (report)
- know.netenrich.com — Cutting%20Kitten (report)
- cfr.org — Operation Cleaver (report)
- securityaffairs.co — Ali Baba Apt Middle East (report)
- scadahacker.com — Cylance%20 %20Operation%20Cleaver%20Report (report)
- cylance.com — Cylance Operation Cleaver Report (report)