Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Leafminer

Also known as: Raspite, LeafMiner

Description

Leafminer is an Iranian threat group that has targeted government organizations and business entities in the Middle East since at least early 2017. (Citation: Symantec Leafminer July 2018)

Goals & Targeting

Targeted Sectors

Energy

AI Analysis

· 4 weeks ago

Executive Summary

Leafminer is an Iranian threat group that has been conducting espionage operations against government organizations and businesses in the Middle East since at least 2017. The group primarily targets the energy sector, with the goal of gathering sensitive information. Leafminer's activities pose a significant threat to organizations operating in this region.

Goals & Targeting

Leafminer's strategic objectives are focused on gathering sensitive information from government organizations and business entities in the Middle East, particularly in the energy sector. The group's targeting profile suggests that they are seeking to gather intelligence on critical infrastructure and key players in the energy sector, with the goal of informing Iranian government policy and decision-making. The group's typical victims include government agencies, energy companies, and other organizations with sensitive information that could be of value to the Iranian government.

Enhanced Description

Leafminer, also known as Raspite or LeafMiner, is a threat group believed to be sponsored by the Iranian government. The group has been active since at least early 2017 and has been responsible for a series of targeted attacks against government organizations and business entities in the Middle East. Leafminer's primary motivation is espionage, and they have been known to target the energy sector in particular. The group's tactics, techniques, and procedures (TTPs) suggest a high degree of sophistication, with a focus on gathering sensitive information from their victims. Leafminer's operations are characterized by a careful and deliberate approach, with the group taking steps to avoid detection and maintain a low profile. The group has been known to use a range of tools and techniques, including custom malware and publicly available hacking tools, to compromise their victims' systems and gather sensitive information. The group's activities have been the subject of several research reports and analyses, including a comprehensive study by Symantec in 2018. The Leafminer group's activities pose a significant threat to organizations operating in the energy sector, particularly those with operations in the Middle East. The group's focus on espionage and their ability to gather sensitive information from their victims make them a highly formidable opponent. As such, it is essential for organizations to be aware of the group's TTPs and to take steps to protect themselves from potential attacks.

Key Capabilities

  • Custom malware development
  • Network exploitation
  • Credential harvesting
  • Data exfiltration
  • Social engineering

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration

ATT&CK Techniques

T1059.007
T1003.004
T1555
T1555.003
T1136.001
T1003.001
T1110.003
T1003.005
T1055.013
T1083
T1552.001
T1588.002
T1114.002
T1027.010
T1189
T1018
T1046

Software / Tooling

Custom RAT
Mimikatz
Cobalt Strike

Campaigns & Victims

Leafminer's campaign patterns suggest a careful and deliberate approach, with the group taking steps to avoid detection and maintain a low profile. The group's operational tempo is characterized by a focus on exploiting vulnerabilities and using social engineering tactics to gain initial access to their victims' systems. Leafminer's past operations have included attacks against government agencies and energy companies in the Middle East, with the goal of gathering sensitive information. Notable past operations include a series of attacks against energy companies in 2017 and 2018, which were attributed to Leafminer by several security researchers.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting
  • Custom malware with anti-analysis techniques

Recommended Actions

  • Implement a robust security awareness training program to educate employees on the risks of spear-phishing and social engineering
  • Conduct regular vulnerability assessments and penetration testing to identify potential weaknesses in systems and networks
  • Implement a robust incident response plan to quickly respond to potential security incidents
  • Use advanced threat detection tools, such as endpoint detection and response (EDR) solutions, to detect and respond to potential threats

Suggested Tags

APT
Espionage
Energy Sector
Iranian Threat Group

Confidence Assessment

The available data on Leafminer suggests a moderate to high confidence level in the group's existence and activities. However, there are still some information gaps, particularly with regards to the group's exact motivations and targeting profile. Further research and analysis are needed to fully understand the group's TTPs and to develop effective countermeasures.

ATT&CK Techniques

Credential Access
7 techniques

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Dragos Raspite Aug 2018 — Dragos, Inc. (2018, August 2). RASPITE. Retrieved November 26, 2018.
  2. Symantec Leafminer July 2018 — Symantec Security Response. (2018, July 25). Leafminer: New Espionage Campaigns Targeting Middle Eastern Regions. Retrieved August 28, 2018.

Intel Summary

17

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

8

Tactics

Tags

APT
Government Targeting
Espionage
Energy Sector
Iranian Threat Group

Details

MITRE ID
G0077
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Iran (IR)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--32bca8ff-d900-4877-aa65-d70baa041b74
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.