Cleaver__2014__Cylance_Operation_Cleaver_Report.pdf
ID: aa9a79f4-8f43-45e7-afde-09f4d2b0e736
STIX ID: report--aa9a79f4-8f43-45e7-afde-09f4d2b0e736
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2014-12-02
Last Modified Date: 2014-12-02
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Operation Cleaver is a Cylance-authored APT report attributing a long-running, Iranian-sponsored campaign (Tarh Andishan) that has targeted more than 50 victims across government and critical infrastructure sectors globally. The document provides technical analysis of multiple custom and repurposed malware families (TinyZBot, PVZ, Net Crawler, zhCat, etc.), detailed TTPs (SQL injection, spear-phishing, credential dumping, lateral movement, SOAP/HTTP C2), attribution evidence (Iranian registrant info, IP/netblocks, code artifacts), and a large set of IOCs (domains, IPs, file hashes, mutexes, YARA rules) plus mitigation guidance and contact information for incident response.
