Cleaver

G0003

Threat group.View on attack.mitre.org

About this group

Cleaver is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver. Strong circumstantial evidence suggests Cleaver is linked to Threat Group 2889 (TG-2889).

Techniques used5

Procedure examples5

TechniqueProcedure example
T1003.001
LSASS Memory

Cleaver has been known to dump credentials using Mimikatz and Windows Credential Editor.

T1557.002
ARP Cache Poisoning

Cleaver has used custom tools to facilitate ARP cache poisoning.

T1585.001
Social Media Accounts

Cleaver has created fake LinkedIn profiles that included profile photos, details, and connections.

T1587.001
Malware

Cleaver has created customized tools and payloads for functions including ARP poisoning, encryption, credential dumping, ASP.NET shells, web backdoors, process enumeration, WMI querying, HTTP and SMB communications, network interface sniffing, and keystroke logging.

T1588.002
Tool

Cleaver has obtained and used open-source tools such as PsExec, Windows Credential Editor, and Mimikatz.

Software4

Campaigns0

None recorded.

References2

  1. Cylance Cleaver Open source
    Cylance. (2014, December). Operation Cleaver. Retrieved September 14, 2017.
  2. Dell Threat Group 2889 Open source
    Dell SecureWorks. (2015, October 7). Suspected Iran-Based Hacker Group Creates Network of Fake LinkedIn Profiles. Retrieved January 14, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.