Uptime Hamster: 16d 7h 10mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Cleaver

Cleaver

1 incidentes 1 paises 0 sectores apt IR Ultimo: 2026-05-25
Aliases: Operation Cleaver, Op Cleaver, Tarh Andishan, Alibaba, TG-2889, G0003, APT CLEAVER
Ver en IntelTracker → APTTrail →
Cleaver, also known as Operation Cleaver or Tarh Andishan, is a state-sponsored cyber espionage group originating from Iran, first publicly exposed in December 2014 but active since at least 2012. This group, assessed with high confidence to be linked to Iranian actors potentially affiliated with the Islamic Revolutionary Guard Corps (IRGC) or Ministry of Intelligence and Security (MOIS), is primarily motivated by long-term intelligence gathering, network infiltration, and the potential for disruptive attacks against critical infrastructure worldwide. What sets Cleaver apart is its sustained focus on comprehensive reconnaissance and its demonstrated capability to compromise sensitive global critical infrastructure, laying groundwork for future potential physical impact.

Aliases del actor

Operation CleaverOp CleaverTarh AndishanAlibabaTG-2889G0003APT CLEAVER

Actores similares

apt-cleaveractor · 1apt-45actor · 2apt-c-27actor · 2apt-c-01actor · 2apt-c-12actor · 1apt-18actor · 1apt-1877teamactor · 1apt-27actor · 1apt-30actor · 1apt-38actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Webunknownwww.cylance.comAPT CLEAVER indicators and references
Repositoriounknowngithub.comAPT CLEAVER indicators and references
Webunknownraw.githubusercontent.comAPT CLEAVER indicators and references
Motivacion