logo

Cleaver__2014__Cylance_Operation_Cleaver_Report.pdf

ID: aa9a79f4-8f43-45e7-afde-09f4d2b0e736

STIX ID: report--aa9a79f4-8f43-45e7-afde-09f4d2b0e736

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2014-12-02

Last Modified Date: 2014-12-02

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Operation Cleaver is a Cylance-authored APT report attributing a long-running, Iranian-sponsored campaign (Tarh Andishan) that has targeted more than 50 victims across government and critical infrastructure sectors globally. The document provides technical analysis of multiple custom and repurposed malware families (TinyZBot, PVZ, Net Crawler, zhCat, etc.), detailed TTPs (SQL injection, spear-phishing, credential dumping, lateral movement, SOAP/HTTP C2), attribution evidence (Iranian registrant info, IP/netblocks, code artifacts), and a large set of IOCs (domains, IPs, file hashes, mutexes, YARA rules) plus mitigation guidance and contact information for incident response.