← All actors Recent activity

Cleaver G0003

CLEAVER

Indicators
15
Source reports
1
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-01-02

Overview 15 indicators

Cleaver is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver. Strong circumstantial evidence suggests Cleaver is linked to Threat Group 2889 (TG-2889).

domain15G0003-domain.txt

Techniques 9 ATT&CK

Open in ATT&CK Navigator → or download the layer (9 techniques, layer 4.5)

Software 4

Principal sources 1 reports

Ranked by how many of this actor's indicators each report brought in.

Timeline 15 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. 15 domain11 yrs ago

    cylance.com/assets/Cleaver/Cylance_Operation_Cleave…

    doosan-job.com
    downloadsservers.com
    drivercenterupdate.com
    easyresumecreatorpro.com
    googleproductupdate.net
    microsoftmiddleast.com
    microsoftserverupdate.com
    microsoftwindowsresources.com
    microsoftwindowsupdate.net
    northropgrumman.net
    teledyne-jobs.com
    windowscentralupdate.com
    windowssecurityupdate.com
    windowsserverupdate.com
    windowsupdateserver.com

Further reading 4