Cleaver is an Iranian nation-state threat actor targeting government, defense, and energy sectors.
Analyst brief
Cleaver (also known as Operation Cleaver, Tarh Andishan) is a nation-state threat actor originating from Iran. The group primarily targets organizations in the government, defense, energy, and technology sectors, especially those operating in or doing business with Saudi Arabia. Its key TTPs involve custom malware like Net Crawler and TinyZBot, along with toolsets like PsExec for lateral movement and Mimikatz for credential dumping via LSASS memory access. Defenders should focus on monitoring for network anomalies linked to Iranian infrastructure, blocking credential access attempts against LSASS, and restricting the use of PsExec across critical systems.
Cleaver
Operation CleaverOp CleaverTarh Andishan
nation-state
A group of cyber actors utilizing infrastructure located in Iran have been conducting computer network exploitation activity against public and private U.S. organizations, including Cleared Defense Contractors (CDCs), academic institutions, and energy sector companies. This threat actor targets entities in the government, energy, and technology sectors that are located in or do business with Saudi Arabia.
origin (suspected)
🇮🇷Iran· state-sponsoredattribution confidence: medium (50)
Monitor process access events to detect attempts to obtain credentials from LSASS Memory and implement network segmentation and monitor suspicious ARP activity to mitigate ARP Cache Poisoning.
FAQ2
What tool does the Cleaver group use to steal credentials from LSASS memory?+
The Cleaver group uses Mimikatz to steal credentials from LSASS memory.
What are the names of the custom malware used by the Cleaver group?+
The custom malware used by the Cleaver group includes 'Net Crawler' and 'TinyZBot'.