Leafminer, also referred to as RASPITE in some reporting, is an intrusion set active since at least 2017 that has primarily targeted government and business entities in the Middle East, with separate reporting linking RASPITE activity to initial access operations against electric utilities in the United States. The activity has been associated with Iranian state-aligned cyber operations, though public reporting has at times treated Leafminer and RASPITE as overlapping or related tracking names rather than fully resolved designations. Leafminer is known for credential-focused intrusion activity, particularly targeting email accounts and stored credentials. Reported tradecraft includes use of publicly available post-exploitation and credential theft tools such as LaZagne, Mimikatz, PsExec, and MailSniper, as well as utilities used to search mail stores and extract attachments. The group has also used JavaScript in infection chains, conducted network and service scanning to identify vulnerable systems, and gathered detailed information from remote hosts using legitimate administrative tooling, including Sysinternals utilities. Observed techniques associated with the group include credential access from files and applications, command obfuscation, exploitation for initial access and installation, remote system and network service discovery, and watering-hole style initial access. In the RASPITE tracking associated with the electric utility sector, the activity has been characterized as focused on gaining footholds in organizations that operate ICS environments, but without publicly demonstrated ICS-specific attack capability. Known aliases include Leafminer and RASPITE.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed in annotations associated with the credential-access technique.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
Referenced as a threat actor associated with the command obfuscation technique using environment variable substrings in Windows command lines.
Referenced in the detection annotations as a threat actor associated with reconnaissance/exploitation behavior relevant to Netspy-style network scanning.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.