EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/espionage-operation/operation-cleaver
300/430

File EL-0131CriticalResolvedEspionage Operation / Cyberattack

Operation Cleaver

Also filed as Operation Cleaver

Operation Cleaver was a sophisticated cyber espionage campaign targeting critical industrial infrastructure within Iran. The operation aimed to gather intelligence and potentially disrupt sensitive facilities, particularly those related to the nuclear program. It demonstrated advanced capabilities in exploiting industrial control systems (ICS) and SCADA networks.

  • #iran
  • #critical-infrastructure
  • #cyberespionage
  • #stuxnet
  • #industrial-control-systems
Notoriety8/10
Event
1 Jan 2014
Disclosed
1 Jan 2013
Target
Iranian Nuclear Program Facilities
Actor
Iran-linked Actor
Scale
Operational Data, Schematics, Process Parameters
Status
Resolved

01Summary

The campaign, attributed to Iran-linked actors, focused on penetrating the operational technology (OT) networks of key Iranian facilities. Unlike purely data-exfiltration operations, Cleaver demonstrated an intent to map, monitor, and potentially sabotage physical processes. The attackers utilized custom malware designed to interact with specific industrial protocols, allowing them to gather detailed schematics and operational parameters. The discovery of these activities highlighted the vulnerability of national critical infrastructure to state-sponsored cyber warfare. The incident significantly raised global awareness regarding the threat posed by cyberattacks against industrial control systems, moving the focus beyond traditional IT networks.

02Background

The escalating international tensions surrounding Iran's nuclear ambitions provided the geopolitical context for such cyber operations. Western intelligence agencies and private security firms have long warned that Iran was developing sophisticated cyber capabilities to protect and advance its strategic interests. Operation Cleaver represents a maturation of these capabilities, moving from simple reconnaissance to targeted operational disruption.

03Key revelations

  1. 01The successful mapping of critical industrial control systems (ICS) within a nation's core infrastructure.
  2. 02The capability to remotely monitor and potentially manipulate physical industrial processes (e.g., valves, pumps).
  3. 03The high level of state-sponsored coordination required to execute such a complex, multi-stage cyber operation.

04Technical analysis

The attack methodology involved multi-stage infiltration, likely starting with spear-phishing or supply chain compromise to gain initial access to the corporate IT network. From there, the threat actors performed extensive internal reconnaissance to map the segregated OT network. The malware deployed was specialized, designed to communicate with and manipulate Programmable Logic Controllers (PLCs) and Human-Machine Interfaces (HMIs), indicating a deep understanding of industrial control system architecture.

Attack vector
Spear-phishing or Supply Chain Compromise (Inferred)
Attack method
Espionage and Reconnaissance (OT Network Mapping)
Initial access
Network Intrusion (Inferred)
Lateral movement
Internal Network Pivoting (IT to OT)
Persistence
Backdoors/Scheduled Tasks (Inferred)
Exfiltration
Encrypted Channels (Inferred)
Tool / malware
Custom ICS Malware (Specific name null)
Malware family
ICS/SCADA Malware
Malware type
Spyware/Manipulator

Vulnerabilities exploited

  • ICS Protocol Vulnerabilities

MITRE ATT&CK techniques

  • T1046
  • T1021.001
  • T1562.001

05Threat actor

The actors linked to Operation Cleaver are believed to be state-sponsored units operating under the direction of the Iranian government. Their profile suggests a highly resourced, technically proficient group specializing in industrial espionage and cyber-physical sabotage.

Aliases

  • Iranian State Actors
  • APT33

APT designations

  • APT33

MITRE groups

  • T0865

Attribution sources

  • Mandiant
  • Cybersecurity Industry Reports

06Victims and impact

Additional victims

  • Iranian Industrial Control Systems (ICS)

Countries affected

  • Iran

07Data exposed

Data types

  • Process Control Data
  • Operational Schematics
  • Personnel Credentials
  • Technical Blueprints

Notable documents

  • ICS Network Diagrams
  • SCADA System Logs
  • Operational Procedure Manuals

08Financial damage

Damage is primarily assessed in terms of operational disruption and intelligence loss, not direct financial theft.

09Timeline

  1. 2010-01-01Start of observed activity/initial infiltration phase.
  2. 2012-12-01Discovery of the intrusion by security researchers.
  3. 2013-01-01Public disclosure of the operation's scope and capabilities.

10Reaction and fallout

Public reaction

The incident prompted a global reassessment of cybersecurity risk, particularly concerning the convergence of IT and OT networks. Governments and private industry increased investment in industrial security protocols.

Political impact

It heightened international scrutiny of Iran's cyber capabilities, contributing to the geopolitical tension surrounding its nuclear program. It reinforced the concept of cyber warfare as a primary tool of state policy.

Geopolitical consequences

The incident contributed to the global trend of 'cyber deterrence,' where nations begin to treat cyberattacks on critical infrastructure as acts of war, potentially triggering retaliatory measures.

11Legal

No specific legal action was taken against the perpetrators, as the operation was state-sponsored espionage. However, it contributed to the development of international norms regarding cyber warfare.

12Aftermath

Policy changes

  • Mandatory OT/IT Network Segmentation
  • Increased focus on ICS/SCADA security standards (e.g., IEC 62443)

Regulatory changes

  • Enhanced national critical infrastructure protection guidelines

Security improvements

  • Implementation of unidirectional gateways between IT and OT networks
  • Advanced threat hunting specifically for industrial protocols

13Significance and legacy

Significance

Operation Cleaver is significant because it marked a clear escalation in cyber warfare, demonstrating the ability to target and map physical industrial processes rather than just stealing data. It established the concept of 'cyber-physical attack' as a credible threat vector, forcing critical infrastructure sectors to overhaul their security architectures.

Legacy

The incident accelerated the global adoption of 'Zero Trust' principles within industrial environments. It also spurred the creation of specialized cyber defense agencies focused solely on Operational Technology (OT) security, recognizing that traditional IT security measures are insufficient.

14Disclosure and media

Authentication
Technical Analysis/Forensics

Media partners

  • Cybersecurity Research Firms

Publishing organisations

  • Mandiant

15Related files

Related events

  • Stuxnet
  • Sandworm

16Field notes

  1. 01The attack required deep knowledge of specific industrial protocols (e.g., Modbus, DNP3) to function.
  2. 02The focus on OT networks means that even if the IT network is secured, the physical plant remains vulnerable.

17Resolution

The specific operation concluded, but the underlying threat posed by state-sponsored ICS attacks remains ongoing and evolving.

18Sources

Official documents

  • Mandiant Threat Reports (Related)

References

  1. [1]Mandiant
  2. [2]Cybersecurity Industry Analysis
Fact sheetEL-0131

Dates

Event
1 Jan 2014
Started
1 Jan 2010
Ended
31 Dec 2012
Discovered
1 Dec 2012
Disclosed
1 Jan 2013
Ongoing
No

Target

Organisation
Natanz Research Reactor Complex (Implied)
Type
Government
Sector
Nuclear Energy / Critical Infrastructure
Country
Iran
Gov. level
Federal

Actor

Name
Iran-linked Actor
Type
Nation-State Actor
Nationality
Iran
Nation-state
Iran
Motivation
Geopolitical destabilization and intelligence gathering against perceived adversaries, specifically Israel and Saudi Arabia.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Operational Data, Schematics, Process Parameters
Sensitivity
Top Secret
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.