Home/Threat Actor/RASPITE (Leafminer)
Threat Actor

RASPITE (Leafminer)

raspite_leafminer · iran_attributed_dragos_tracked_ics_threat_group_2017_active · active since 2017-01

RASPITE (also tracked by Symantec as Leafminer) is Dragos's canonical Iran-attributed Activity Group designation for an ICS-targeting threat group active since at least 2017 targeting electric utilities in the United States + government entities in the Middle East per SecurityWeek canonical 2019 Dragos coverage ("First detailed last year and believed to be operating out of Iran, the group tracked as RASPITE targets electric utilities in the United States, as well as government entities in the Middle East"); Iran-attribution via Dragos canonical 2018 RASPITE disclosure + Symantec independent Leafminer 2018 alternative tracking + SecurityWeek canonical Nine Distinct Threat Groups Targeting Industrial Systems coverage + SecurityWeek More Threat Groups Target Electric Utilities in North America coverage + Bleeping Computer canonical 2020 Dragos coverage ("Raspite - active since at least 2017, targets the utility sector political and strategic targets in the Middle East") + Dragos threat groups summary 2025 ("RASPITE: Credential capture and LOTL techniques employed for initial access, reconnaissance C2")

honest attribution caveat Iran-attribution is based on Dragos + Symantec industry assessments with limited public technical attribution evidence detailed in publicly-available reporting + documentation density thinner than CHERNOVITE + KAMACITE clusters reflecting limited Iran- attributed ICS-focused activity group public reporting.

standalone cluster paralleling chernovite_pipedream + kamacite + covellite_lazarus_ics in v0.1.166 OT/ICS Dragos- taxonomy actor cluster cell.

operational target profile signature electric utilities in United States + government entities in Middle East dual- target-set per Dragos canonical 2018 disclosure + Saudi Arabia + Japan + Western Europe historic victims through mid-2018 per Dragos ("While additional victims have been identified in Saudi Arabia, Japan, and Western Europe, they were not part of the actor's activity since mid-2018") + utility sector political + strategic targets in Middle East per Bleeping Computer Dragos coverage; operational attack architecture: (1) cluster- defining 2017 operational origin with Iran attribution establishing post-Stuxnet Iranian ICS-focused activity group emergence pattern; (2) cluster-defining Symantec Leafminer 2018 alternative tracking signature establishing cross-vendor attribution agreement with Symantec independent Iranian APT designation.

(3) cluster- defining Dragos canonical 2018 RASPITE public disclosure with US electric utility + Middle East government dual-target-set.

(4) cluster-defining mid-2018 target-set narrowing signature with Saudi Arabia + Japan + Western Europe victim activity terminating + US electric utilities + Middle East government remaining primary focus post-mid-2018.

(5) cluster- defining credential capture + Living-Off-The-Land (LOTL) techniques tradecraft per Dragos 2025 threat groups summary ("RASPITE: Credential capture and LOTL techniques employed for initial access, reconnaissance C2")

(6) signature ICS Cyber Kill Chain Stage 1 reconnaissance + initial access focus assessment per Dragos without demonstrated Stage 2 disruptive capability distinguishing RASPITE from ELECTRUM + XENOTIME disruption-capable actors.

(7) signature publicly- available credential capture tools tradecraft + built-in system tools usage continuing post-2025 Dragos tracking.

(8) signature multi-region operational footprint (US + Middle East primary + Saudi Arabia + Japan + Western Europe historic) reflecting broader Iran-aligned cyber strategy patterns.

(9) signature utility sector political + strategic targets focus consistent with Iran- regional-rival surveillance objectives; cluster fills the Dragos-RASPITE-Iran-attributed ICS-Activity-Group + Symantec-Leafminer-alternative- tracking + 2017-active-since + US-electric-utility- targeting + Middle-East-government-entity-targeting + Saudi-Arabia-Japan-Western-Europe-historic- victims + credential-capture-LOTL-tradecraft + ICS-Cyber-Kill-Chain-Stage-1-reconnaissance-focus position in OT/ICS Dragos-taxonomy actor cluster cell.

canonical illustration of Iran-attributed ICS-targeting Activity Group per Dragos taxonomy + US electric utility + Middle East government dual-target-set signature + credential-capture- LOTL operational tradecraft + ICS Cyber Kill Chain Stage 1 reconnaissance-focus assessment + Symantec Leafminer cross-vendor attribution agreement cited in essentially all subsequent Iran-attributed ICS-targeting industry analyses through 2017-2026 period.

iran_attributed_dragos_tracked_ics_threat_group_2017_active confidence: high 16 aliases MITRE ATT&CK G0077 ↗
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

RASPITE (also tracked by Symantec as Leafminer) is Dragos's canonical Iran-attributed Activity Group designation for an ICS-targeting threat group active since at least 2017 targeting electric utilities in the United States + government entities in the Middle East. Iran-attribution via Dragos canonical 2018 disclosure + Symantec independent Leafminer 2018 tracking + SecurityWeek + Bleeping Computer industry coverage. Honest attribution caveat: Iran-attribution is based on Dragos + Symantec industry assessments with limited public technical attribution evidence detailed in publicly-available reporting.

Documentation density thinner than other ICS taxonomy clusters reflecting limited Iran- attributed ICS-focused activity group public reporting. Standalone cluster paralleling chernovite_pipedream + kamacite + covellite_lazarus_ics in v0.1.166 OT/ICS Dragos-taxonomy actor cluster cell.

Operational target profile
  • Electric utilities US signature.
  • Government entities Middle East signature.
  • Saudi Arabia + Japan + Western Europe historic victims (not active since mid-2018) Operational attack architecture: (1) 2017 origin + Iran attribution (cluster- defining) (2) Symantec Leafminer 2018 alternative tracking (cluster-defining) (3) US electric utility + Middle East government dual-target-set (cluster-defining) (4) Credential capture + LOTL techniques (cluster-defining) (5) ICS Cyber Kill Chain Stage 1 reconnaissance focus (signature) (6) Mid-2018 target-set narrowing (signature) The cluster fills the Dragos-RASPITE-Iran-attributed ICS-Activity-Group + Symantec-Leafminer-alternative- tracking + 2017-active-since + US-electric-utility- targeting + Middle-East-government-entity-targeting + Saudi-Arabia-Japan-Western-Europe-historic- victims + credential-capture-LOTL-tradecraft + ICS-Cyber-Kill-Chain-Stage-1-reconnaissance-focus position in OT/ICS Dragos-taxonomy actor cluster cell.

Aliases

16
raspite_leafminerraspiteraspite activity groupleafminerleafminer aptleafminer iranian threat groupdragos raspite trackingraspite iran-attributed dragos 2018 disclosureraspite us electric utility targetingraspite middle east government entity targetingraspite saudi arabia japan western europe historic victimsraspite credential capture lotl tradecraft signatureraspite electric utility north america targetingsymantec leafminer 2018 disclosureleafminer iranian apt threat actorraspite ics-cyber-kill-chain stage-1 reconnaissance

Notable Campaigns

7
2018RASPITE Symantec Leafminer 2018 Alternative Tracking Signature
2018RASPITE Dragos Canonical 2018 Disclosure + US Electric Utility Targeting Signature
2018RASPITE Mid-2018 Target Set Narrowing Signature
2017-2026Continued Industry Reference Status (2017-2026)
2017-2025RASPITE Credential Capture + LOTL Tradecraft Signature
2017-2025RASPITE ICS Cyber Kill Chain Stage 1 Reconnaissance Focus Signature
2017RASPITE Origin, 2017 Iran-Attributed ICS Targeting

Attribution & Reporting

Attributed by
Dragos (canonical RASPITE Iran-attributed Activity Group designation 2018+)Symantec (canonical Leafminer 2018 alternative tracking + initial Iranian APT designation)SecurityWeek (canonical Nine Distinct Threat Groups Targeting Industrial Systems Dragos coverage)Bleeping Computer (canonical 2020 Dragos coverage)Dragos threat groups summary (2025 RASPITE LOTL tradecraft addition)
Key reporting
reportDragos: canonical RASPITE Iran-attributed Activity Group designation (2018+ tracking)
reportSymantec: canonical Leafminer 2018 alternative tracking + initial Iranian APT designation
reportSecurityWeek: Nine Distinct Threat Groups Targeting Industrial Systems Dragos coverage (2019)
reportSecurityWeek: More Threat Groups Target Electric Utilities in North America coverage
reportBleeping Computer: New Actors Attack Industrial Control Systems Old Ones Mature (2020 Dragos coverage)
reportDragos threat groups summary (2025): RASPITE LOTL tradecraft addition

Operational

State sponsor

RASPITE (also tracked by Symantec as Leafminer) is Dragos's canonical Iran-attributed designation for an ICS-targeting threat group active since at least 2017. Per SecurityWeek covering Dragos reporting: "First detailed last year and believed to be operating out of Iran, the group tracked as RASPITE targets electric utilities in the United States, as well as government entities in the Middle East.

" Per Bleeping Computer 2020 Dragos coverage: "Raspite
  • active since at least 2017, targets the utility sector (political and strategic targets in the Middle East)." Honest attribution caveat: Iran-attribution is based on Dragos + Symantec independent industry assessments with limited public technical attribution evidence detailed in publicly- available reporting. Documentation density for RASPITE/Leafminer is thinner than for CHERNOVITE + KAMACITE clusters reflecting limited public reporting on Iran-attributed ICS-focused activity groups. Symantec Leafminer 2018 disclosure established initial Iranian APT framing. Attribution chain: (1) Dragos canonical 2018 RASPITE disclosure with Iran attribution: per SecurityWeek covering Dragos: "First detailed last year and believed to be operating out of Iran, the group tracked as RASPITE targets electric utilities in the United States, as well as government entities in the Middle East. While additional victims have been identified in Saudi Arabia, Japan, and Western Europe, they were not part of the actor's activity since mid-2018." (2) Symantec Leafminer 2018 alternative tracking canonical: Symantec tracks the same Iranian APT activity as Leafminer in 2018 disclosure establishing initial Iranian-threat-actor designation in industry tracking. (3) Dragos 2020 + 2025 RASPITE tradecraft summary: per Dragos threat groups summary 2025: "RASPITE: Credential capture and LOTL techniques employed for initial access, reconnaissance C2." Per Bleeping Computer 2020: "Raspite.
  • active since at least 2017, targets the utility sector (political and strategic targets in the Middle East)." (4) Industry assessment ICS-Cyber-Kill-Chain Stage-1 focus: RASPITE assessed at ICS Cyber Kill Chain Stage 1 (reconnaissance + initial access) without demonstrated Stage 2 disruptive capability per Dragos.
Operational target profile
  • Electric utilities in United States signature per Dragos.
  • Government entities in Middle East signature per Dragos.
  • Saudi Arabia historic victim per Dragos.
  • Japan historic victim per Dragos.
  • Western Europe historic victim per Dragos.
  • Utility sector political + strategic targets in Middle East per Bleeping Computer Dragos.
  • Not active mid-2018+ per Dragos for non-US- electric-utility + non-Middle-East-government target sets The cluster fills the Dragos-RASPITE-Iran-attributed ICS-Activity-Group + Symantec-Leafminer-alternative- tracking + 2017-active-since + US-electric-utility- targeting + Middle-East-government-entity-targeting + Saudi-Arabia-Japan-Western-Europe-historic- victims + credential-capture-LOTL-tradecraft + ICS-Cyber-Kill-Chain-Stage-1-reconnaissance-focus position in OT/ICS Dragos-taxonomy actor cluster cell.
Motivations
iran_attributed_ics_focused_threat_actor_dragos_designation, us_electric_utility_reconnaissance_initial_access_signature, middle_east_government_entity_targeting_signature, credential_capture_lotl_living_off_the_land_tradecraft_signature, ics_cyber_kill_chain_stage_1_reconnaissance_focus_signature
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)51/60 · 85%
Analytics (MITRE CAR)31/60 · 51%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MIDDLE EAST GOVERNMENT TARGETING SIGNATURESAUDI ARABIA JAPAN WESTERN EUROPE HISTORIC VICTIM SET
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin