Leafminer

MITRE ATT&CK: G0077 View on attack.mitre.org

Aliases: Raspite, LeafMiner, Leafminer

First seen
2017-01-01 00:00:00
Primary motivation
espionage
Sophistication
intermediate
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:53:07

Targeted industries: government-and-public-sector energy-and-utilities technology-and-telecommunications

Targeted regions: country_code:sa country_code:ae country_code:qa country_code:om

Context

Leafminer is an Iranian threat group that has targeted government organizations and business entities in the Middle East since at least early 2017.

Detection coverage

  • 8 YARA rules
  • 241 Sigma rules

Malware & tools used

  • Command Obfuscation (attack-pattern)
  • Tool (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Credentials from Password Stores (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Cached Domain Credentials (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Credentials In Files (attack-pattern)
  • LSA Secrets (attack-pattern)
  • Process Doppelgänging (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Password Spraying (attack-pattern)
  • Local Account (attack-pattern)
  • JavaScript (attack-pattern)
  • Remote Email Collection (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • MailSniper (malware)
  • Mimikatz (malware)
  • LaZagne (malware)
  • PsExec (malware)

Reports & references

  • dragos.com — 20180802Raspite (report)
  • Broadcom/Symantec — Leafminer Espionage Middle East (report)
  • MITRE ATT&CK — G0077 (report)
  • dragos.com — 20180802Raspite (report)
  • Broadcom/Symantec — Leafminer Espionage Middle East (report)

External references