Cleaver

๐Ÿ”ด High
Also known as: Alibaba, APT 34, APT34, ATK40, Cleaver, Cobalt Gypsy, Crambus, Earth Simnavaz, EUROPIUM, Evasive Serpens, G0003, G0049, Hazel Sandstorm, HELIX KITTEN, Helix Kitten, IRN2, OilRig, Op Cleaver, Operation Cleaver, TA452, Tarh Andishan, TG-2889, Threat Group 2889, Twisted Kitten

Cleaver is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver. Cylance Cleaver Strong circumstantial evidence suggests Cleaver is linked to Threat Group 2889 (TG-2889). Dell Threat Group 2889

๐ŸŒ Country Iran
๐Ÿ“… Activity 2014 โ€” 2014
โšก Risk Level High
๐ŸŽฏ Incident Type Espionage
๐Ÿงญ ATT&CK G0003
Defense Energy Technology Government, Administration Academia - University Private sector Government Chemical Engineering Finance Telecoms Other Civil society
2014
2014

Introduction

Cleaver is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver. Cylance Cleaver Strong circumstantial evidence suggests Cleaver is linked to Threat Group 2889 (TG-2889). Dell Threat Group 2889

Activities and Tactics

Targeted Sectors: Defense, Energy, Technology, Government, Administration, Academia - University, Private sector, Government, Chemical, Engineering, Finance, Telecoms, Other, Civil society

Country of Origin: ๐Ÿ‡ฎ๐Ÿ‡ท Iran

Risk Level: High

First Seen: 2014

Last Activity: 2014

Incident Type: Espionage

Suspected Victims: Canada, France, Israel, Mexico, Saudi Arabia, China, Germany, United States, Pakistan, South Koreaโ€ฆ

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No atomic indicators are listed in this profile. The APTnotes snapshot indexes 1 public reports that may contain IOCs; see Source Attribution for dataset links.

Malware and Tools

  • CyberGate
  • Arabian-Attacker RAT
  • Cyber Eye RAT
  • Xploit

MITRE ATT&CK Software

Attribution and Evidence

Country of Origin: Iran Additional attribution information pending cataloguing.

References

[1] mitre-attack [5] Cylance Cleaver Cylance. (2014, December). Operation Cleaver. Retrieved September 14, 2017. [6] Dell Threat Group 2889 Dell SecureWorks. (2015, October 7). Suspected Iran-Based Hacker Group Creates Network of Fake LinkedIn Profiles. Retrieved January 14, 2016.