RASPITE (Leafminer)
RASPITE (also tracked by Symantec as Leafminer) is Dragos's canonical Iran-attributed Activity Group designation for an ICS-targeting threat group active since at least 2017 targeting electric utilities in the United States + government entities in the Middle East per SecurityWeek canonical 2019 Dragos coverage ("First detailed last year and believed to be operating out of Iran, the group tracked as RASPITE targets electric utilities in the United States, as well as government entities in the Middle East"); Iran-attribution via Dragos canonical 2018 RASPITE disclosure + Symantec independent Leafminer 2018 alternative tracking + SecurityWeek canonical Nine Distinct Threat Groups Targeting Industrial Systems coverage + SecurityWeek More Threat Groups Target Electric Utilities in North America coverage + Bleeping Computer canonical 2020 Dragos coverage ("Raspite - active since at least 2017, targets the utility sector political and strategic targets in the Middle East") + Dragos threat groups summary 2025 ("RASPITE: Credential capture and LOTL techniques employed for initial access, reconnaissance C2")
honest attribution caveat Iran-attribution is based on Dragos + Symantec industry assessments with limited public technical attribution evidence detailed in publicly-available reporting + documentation density thinner than CHERNOVITE + KAMACITE clusters reflecting limited Iran- attributed ICS-focused activity group public reporting.
standalone cluster paralleling chernovite_pipedream + kamacite + covellite_lazarus_ics in v0.1.166 OT/ICS Dragos- taxonomy actor cluster cell.
operational target profile signature electric utilities in United States + government entities in Middle East dual- target-set per Dragos canonical 2018 disclosure + Saudi Arabia + Japan + Western Europe historic victims through mid-2018 per Dragos ("While additional victims have been identified in Saudi Arabia, Japan, and Western Europe, they were not part of the actor's activity since mid-2018") + utility sector political + strategic targets in Middle East per Bleeping Computer Dragos coverage; operational attack architecture: (1) cluster- defining 2017 operational origin with Iran attribution establishing post-Stuxnet Iranian ICS-focused activity group emergence pattern; (2) cluster-defining Symantec Leafminer 2018 alternative tracking signature establishing cross-vendor attribution agreement with Symantec independent Iranian APT designation.
(3) cluster- defining Dragos canonical 2018 RASPITE public disclosure with US electric utility + Middle East government dual-target-set.
(4) cluster-defining mid-2018 target-set narrowing signature with Saudi Arabia + Japan + Western Europe victim activity terminating + US electric utilities + Middle East government remaining primary focus post-mid-2018.
(5) cluster- defining credential capture + Living-Off-The-Land (LOTL) techniques tradecraft per Dragos 2025 threat groups summary ("RASPITE: Credential capture and LOTL techniques employed for initial access, reconnaissance C2")
(6) signature ICS Cyber Kill Chain Stage 1 reconnaissance + initial access focus assessment per Dragos without demonstrated Stage 2 disruptive capability distinguishing RASPITE from ELECTRUM + XENOTIME disruption-capable actors.
(7) signature publicly- available credential capture tools tradecraft + built-in system tools usage continuing post-2025 Dragos tracking.
(8) signature multi-region operational footprint (US + Middle East primary + Saudi Arabia + Japan + Western Europe historic) reflecting broader Iran-aligned cyber strategy patterns.
(9) signature utility sector political + strategic targets focus consistent with Iran- regional-rival surveillance objectives; cluster fills the Dragos-RASPITE-Iran-attributed ICS-Activity-Group + Symantec-Leafminer-alternative- tracking + 2017-active-since + US-electric-utility- targeting + Middle-East-government-entity-targeting + Saudi-Arabia-Japan-Western-Europe-historic- victims + credential-capture-LOTL-tradecraft + ICS-Cyber-Kill-Chain-Stage-1-reconnaissance-focus position in OT/ICS Dragos-taxonomy actor cluster cell.
canonical illustration of Iran-attributed ICS-targeting Activity Group per Dragos taxonomy + US electric utility + Middle East government dual-target-set signature + credential-capture- LOTL operational tradecraft + ICS Cyber Kill Chain Stage 1 reconnaissance-focus assessment + Symantec Leafminer cross-vendor attribution agreement cited in essentially all subsequent Iran-attributed ICS-targeting industry analyses through 2017-2026 period.