Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cylance’s December 2, 2014 report described a two-year investigation into intrusions it named Operation Cleaver, and assessed the campaign as linked to Iran. The report documented a broad set of targets and intrusion techniques, but its evidence for attempted access is not the same as proof of successful, deep compromise, Iranian state direction, or a capacity to cause physical damage.

What Cylance said Operation Cleaver was

Cylance described Operation Cleaver as a campaign it had tracked for two years before publishing Operation Cleaver: Critical Infrastructure at Risk on December 2, 2014. The report said the campaign targeted organizations across a wide range of sectors and countries. Its scope makes the report significant as a vendor account of suspected intrusions, but the label “target” should not be read as meaning every listed organization was successfully compromised.

Cylance listed organizations or targets in 16 countries: Canada, China, England, France, Germany, India, Israel, Kuwait, Mexico, Pakistan, Qatar, Saudi Arabia, South Korea, Turkey, the United Arab Emirates, and the United States. The sectors included military, oil and gas, energy and utilities, transportation, airlines and airports, hospitals, telecommunications, technology, education, aerospace, defense, chemicals, manufacturing, and government. The report’s country and sector lists do not establish that every organization experienced the same kind or depth of access.

What evidence Cylance presented for an Iran connection

Cylance pointed to several kinds of operator and infrastructure clues: Persian-language names and artifacts, domains registered in Iran, infrastructure registered to Tarh Andishan, Iranian source network blocks, and hosting through an Iranian provider. The report also described tools that checked whether an external IP address traced to Iran. Taken together, these details formed the basis of the vendor’s Iran-link assessment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The report stated, “We believe this work was sponsored by Iran.” That is Cylance’s attribution, not an independently established identification of a particular Iranian government agency or service. The report also placed state sponsorship among claims in a section titled “Speculation,” alongside the possibility that the operators intended to damage industrial control systems. Those strategic interpretations go beyond the observation that Iranian-linked infrastructure or artifacts appeared in an investigation.

What techniques the report described

Cylance said the intrusions used multiple routes to seek access, including SQL injection, web attacks, and deception-based attacks. It also reported exploitation of the MS08-067 vulnerability and Windows privilege escalation. The report’s described custom tooling included credential dumping, backdoors, process enumeration, Windows Management Instrumentation (WMI) queries, network sniffing, and keystroke logging.

These are techniques Cylance said it observed or collected evidence of; they should not be treated as independently validated findings for every target network. Nor do the presence of familiar techniques or custom tools, by themselves, establish how much access an operator gained or what it intended to do afterward.

How to interpret the report’s numbers

Cylance reported the following figures for its own investigation and disclosure. They are not an independently audited tally of victims or successful intrusions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Figure What Cylance said it counted
16 countries Countries listed in the report’s target section.
More than 8 GB Material collected over two years, including exfiltrated data, tools, victim logs, and reconnaissance data.
More than 80,000 files Files Cylance said it had collected during its investigation.
More than 150 indicators of compromise and samples Indicators and samples Cylance said it was releasing.

The figures describe the vendor’s investigative material and release, not the number of confirmed victims, the volume stolen from any single organization, or the extent of operational impact.

What contemporary criticism said the evidence could not establish

In a December 3, 2014 interview with IranWire, Iran specialist Collin Anderson said the basic claim that Iranian actors attempted to compromise institutions was likely true, while cautioning against broader conclusions. He argued that targeting or compromising employees does not demonstrate a significant compromise of critical infrastructure, prove intent to cause physical harm, or establish the capability to carry out a physical attack. Anderson also criticized the report’s rhetoric and noted that much of the described tooling resembled openly available technology. His criticism is a contemporaneous qualification of the report’s implications, not proof that the intrusion claims were false.

The distinction is important: evidence of an attempted intrusion, evidence of access, evidence of control over critical systems, and evidence of an intention or ability to cause physical consequences are different claims. Cylance’s report supplied its own account of the first categories and an attribution argument; its prediction of possible physical danger was not independent confirmation that such harm was imminent or likely.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How reliable is the Operation Cleaver report?

The most defensible reading is that Operation Cleaver is a vendor investigation presenting evidence Cylance interpreted as Iran-linked activity, with a claim of attempted compromises that Anderson considered plausible. The public account does not establish an independent definitive count of successful intrusions, the depth of access across targets, Iranian state direction, or an intent to cause physical harm. Cylance itself wrote, “We believe our visibility into this campaign represents only a fraction of Operation Cleaver’s full scope,” and warned that “it is only a matter of time before the world’s physical safety is impacted by it.” These are report statements expressing Cylance’s assessment and prediction, not independently verified outcomes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For readers assessing claims about Operation Cleaver, keep four distinctions in view: observed artifacts versus attribution inference; targets versus confirmed compromises; technical access versus physical impact; and the vendor’s contemporary account versus independent or expert criticism.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.