Cleaver is an Iranian state-linked threat actor tracked since at least 2014 and commonly associated with broad espionage-oriented intrusions against aviation, energy, military, transportation, health care, and utilities organizations. Reported targeting has spanned multiple countries, including China, France, Germany, India, Israel, Saudi Arabia, and the United States. The group is also referenced under the aliases Threat Group 2889 and threat_group_2889. Cleaver is known for combining social engineering, credential theft, and post-compromise tooling with both customized malware and dual-use utilities. A notable aspect of its tradecraft is the use of fake LinkedIn personas, including fabricated profile details and connections, to support targeting and victim engagement. After gaining access, the group has been associated with credential dumping activity, including use of Mimikatz and Windows Credential Editor, as well as use of PsExec and other legitimate or openly available administrative tools to facilitate lateral movement and follow-on operations. The actor has also developed or deployed tailored tools and payloads for functions including ARP poisoning, encryption, credential dumping, ASP.NET shells, web backdoors, process enumeration, WMI querying, HTTP and SMB communications, network interface sniffing, and keystroke logging. This indicates an operational model that blends commodity tooling with bespoke capabilities for persistence, collection, internal reconnaissance, and command-and-control. Cleaver is widely assessed as part of the Iranian cyber threat ecosystem and has been included in reporting on active Iranian intrusion groups. Its observed behavior is consistent with long-term network access, credential harvesting, and stealthy post-exploitation activity rather than purely opportunistic crimeware operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Identified as one of the most active APT groups of 2025 in NSFOCUS's annual report.
Known to perform credential dumping.
Listed in the detection annotations/MITRE attack groups metadata; no specific activity, targeting, or use of this Veeam exploitation is attributed in the content.
Listed in the detection annotation as a mapped threat actor associated with the analytic.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.