Leafminer, also referred to as RASPITE, is an Iranian threat actor active since at least 2017 that has targeted government and business victims in the Middle East, with a particular focus on email accounts and credential collection. The group is associated with initial access activity and has been observed operating against organizations in the electric utility sector, including environments with industrial control system exposure, although no confirmed ICS-specific capability has been demonstrated. Leafminer has used JavaScript-based infection chains for execution and has relied heavily on credential theft to expand and maintain access. Reported tooling includes LaZagne for harvesting login and password information, Mimikatz for credential dumping, PsExec for remote execution and lateral movement, and MailSniper for searching mailboxes and desktop content. The actor has also used utilities to extract attachments from email stores, searched for credentials in files, and stolen passwords from browsers and saved mail. Additional observed behavior includes scanning network services for vulnerabilities and using Sysinternals tools to gather information about remote systems. The group’s tradecraft aligns with espionage-oriented intrusion activity centered on reconnaissance, credential access, and post-compromise expansion rather than disruptive or ransomware operations. Known aliases include RASPITE and Leafminer.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed in annotations associated with the credential-access technique.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
Referenced as a threat actor associated with the command obfuscation technique using environment variable substrings in Windows command lines.
Referenced in the detection annotations as a threat actor associated with reconnaissance/exploitation behavior relevant to Netspy-style network scanning.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.