Leafminer
MITRE ATT&CK: G0077 View on attack.mitre.org
Aliases: Raspite, LeafMiner, Leafminer
- First seen
- 2017-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:53:07
Targeted industries: government-and-public-sector energy-and-utilities technology-and-telecommunications
Targeted regions: country_code:sa country_code:ae country_code:qa country_code:om
Context
Leafminer is an Iranian threat group that has targeted government organizations and business entities in the Middle East since at least early 2017.
Detection coverage
- 8 YARA rules
- 241 Sigma rules
Malware & tools used
- Command Obfuscation (attack-pattern)
- Tool (attack-pattern)
- LSASS Memory (attack-pattern)
- Credentials from Password Stores (attack-pattern)
- Network Service Discovery (attack-pattern)
- Cached Domain Credentials (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Credentials In Files (attack-pattern)
- LSA Secrets (attack-pattern)
- Process Doppelgänging (attack-pattern)
- Drive-by Compromise (attack-pattern)
- Remote System Discovery (attack-pattern)
- Password Spraying (attack-pattern)
- Local Account (attack-pattern)
- JavaScript (attack-pattern)
- Remote Email Collection (attack-pattern)
- File and Directory Discovery (attack-pattern)
- MailSniper (malware)
- Mimikatz (malware)
- LaZagne (malware)
- PsExec (malware)
Reports & references
- dragos.com — 20180802Raspite (report)
- Broadcom/Symantec — Leafminer Espionage Middle East (report)
- MITRE ATT&CK — G0077 (report)
- dragos.com — 20180802Raspite (report)
- Broadcom/Symantec — Leafminer Espionage Middle East (report)