# Cleaver

> As of 2026-09-09, Cleaver is a Iran / North Korea (Cleaver, Lazarus); TA505 is non-state financially motivated-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning threat intel, apt. Also known as TA505, Lazarus Group. ATT&CK coverage spans 44 techniques across 15 tactics in 3 of 3 tracked threats. Most-observed techniques: AML.T0008 (Acquire Infrastructure), AML.T0024.002 (Exfiltration via AI Inference API: Extract AI Model), AML.T0040 (AI Model Inference API Access).

- **Nation:** Iran / North Korea (Cleaver, Lazarus); TA505 is non-state financially motivated
- **Tracked threats:** 3
- **Categories:** THREAT_INTEL, APT
- **Also known as:** TA505, Lazarus Group
- **As of:** 2026-09-09

## ATT&CK techniques observed

44 techniques observed across 3 of 3 tracked threats. Tactics: Resource Development (6), Stealth (formerly Defense Evasion) (6), Exfiltration (5), Command and Control (4), Discovery (4), Initial Access (4).

- AML.T0008 Acquire Infrastructure — Resource Development — observed in 2 of 3 tracked threats
- AML.T0024.002 Exfiltration via AI Inference API: Extract AI Model — Exfiltration — observed in 2 of 3 tracked threats
- AML.T0040 AI Model Inference API Access — AI Model Access (ATLAS) — observed in 2 of 3 tracked threats
- AML.T0042 Verify Attack — AI Attack Staging (ATLAS) — observed in 2 of 3 tracked threats
- [AML.T0051](https://intel.threadlinqs.com/technique/AML.T0051) LLM Prompt Injection — Execution — observed in 2 of 3 tracked threats
- [AML.T0054](https://intel.threadlinqs.com/technique/AML.T0054) LLM Jailbreak — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1048](https://intel.threadlinqs.com/technique/T1048) Exfiltration Over Alternative Protocol — Exfiltration — observed in 2 of 3 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 2 of 3 tracked threats
- [T1583.003](https://intel.threadlinqs.com/technique/T1583.003) Virtual Private Server — Resource Development — observed in 2 of 3 tracked threats
- AML.T0024 Exfiltration via AI Inference API — Exfiltration — observed in 1 of 3 tracked threats
- AML.T0048 External Harms — Impact — observed in 1 of 3 tracked threats
- AML.T0048.004 External Harms: AI Intellectual Property Theft — Impact — observed in 1 of 3 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 1 of 3 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 1 of 3 tracked threats

## Tracked threats

- [China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Models](https://intel.threadlinqs.com/threat/TL-2026-2413) — CRITICAL
- [China-Based AI Companies Conducting Industrial-Scale Knowledge Distillation Campaigns Against U.S. Frontier AI Models](https://intel.threadlinqs.com/threat/TL-2026-2405) — HIGH
- [NSFOCUS 2025 APT Group Research Annual Report: 662 Active APT Groups, 42 Newly Disclosed, AI-Weaponized Attacks Surge 89% YoY](https://intel.threadlinqs.com/threat/TL-2026-1559) — MEDIUM

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Cleaver
