← Threat Actors / Iran / Cleaver
DOSSIER // CLEAVER

Cleaver

▲ High Threat Iran
Primary Aliases: Alibaba Cobalt Gypsy G0003 Op Cleaver
Sponsor / State Affiliation Iran (Islamic Republic of)
Primary Motivation Espionage
Active Timeline Unknown – Present
Confidence Rating 70% (Grounded)

A group of cyber actors utilizing infrastructure located in Iran have been conducting computer network exploitation activity against public and private U.S. organizations, including Cleared Defense Contractors (CDCs), academic institutions, and energy sector companies. This threat actor targets entities in the government, energy, and technology sectors that are located in or do business with Saudi Arabia.

⚔️ Weaponized CVE Matrix (0)

No specific weaponized CVEs currently mapped in the public baseline.

🎯 Target Sectors & Focus

Private sector Government Defense Energy Technology Government, Administration Academia - University

🛡️ MITRE ATT&CK® Attack Lifecycle (5 TTPs)

📥 Download Navigator JSON
Copied to clipboard

LINK COPIED TO CLIPBOARD