← Back to SOC feed Coverage →

Malware or hack tool used by attackers in Operation Cleaver

yara HIGH Yara-Rules
backdoorcommunity
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-05-31T23:00:00Z · Confidence: medium

Hunt Hypothesis

Attackers in Operation Cleaver are likely using specific malware or hack tools to execute their attacks, which could indicate a targeted and sophisticated threat. Proactively hunting for these indicators in Azure Sentinel can help identify and mitigate advanced threats before they cause significant damage.

YARA Rule

rule OPCLEAVER_SmartCopy2
{

    meta:
        description = "Malware or hack tool used by attackers in Operation Cleaver"
        reference = "http://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf"
        date = "2014/12/02"
        author = "Cylance Inc."
        score = "70"

    strings:
        $s1 = "SmartCopy2.Properties"
        $s2 = "ZhuFrameWork"

    condition:
        all of them
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 2 string patterns in its detection logic.

References

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/malware/APT_OPCleaver.yar