Leafminer
Also known as: Raspite
Overview
Leafminer is an Iranian threat group that has targeted government organizations and business entities in the Middle East since at least early 2017.
Naming & attribution
Leafminer is tracked under 2 names across the industry. It uses 17 documented ATT&CK techniques — more than 48% of the 174 groups tracked here. Activity attributed since 2017.
| Name | First reported by |
|---|---|
| Raspite | Dragos, Inc |
| LeafMiner | Symantec Security Response |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1055.013Process Doppelgänging — used by 1 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- APT33 Iran — 8 shared techniques (20% overlap)
- FIN6 — 8 shared techniques (16% overlap)
- Fox Kitten Iran — 7 shared techniques (14% overlap)
- MuddyWater Iran — 10 shared techniques (13% overlap)
- HEXANE — 6 shared techniques (13% overlap)
- Play — 5 shared techniques (13% overlap)
Targets
Energy
TTPs — 17 techniques across 8 tactics
Resource Development
-
T1588.002Tool
Initial Access
-
T1189Drive-by Compromise
Execution
-
T1059.007JavaScript
Persistence
-
T1136.001Local Account
Stealth
-
T1027.010Command Obfuscation -
T1055.013Process Doppelgänging
Credential Access
-
T1003.001LSASS Memory -
T1003.004LSA Secrets -
T1003.005Cached Domain Credentials -
T1110.003Password Spraying -
T1552.001Credentials In Files -
T1555Credentials from Password Stores -
T1555.003Credentials from Web Browsers
Discovery
-
T1018Remote System Discovery -
T1046Network Service Discovery -
T1083File and Directory Discovery
Collection
-
T1114.002Remote Email Collection
Tools & malware (4)
LaZagne · Mimikatz · MailSniper · PsExec
Reporting (2)
- RASPITE — Dragos, Inc
- Leafminer: New Espionage Campaigns Targeting Middle Eastern Regions — Symantec Security Response