AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Leafminer
Aliases: Raspite
Leafminer is an Iranian threat group that has targeted government organizations and business entities in the Middle East since at least early 2017.
Open interactive actor investigation
ATT&CK techniques
Command ObfuscationT1588.002
ToolT1003.001
LSASS MemoryT1555
Credentials from Password StoresT1046
Network Service DiscoveryT1003.005
Cached Domain CredentialsT1555.003
Credentials from Web BrowsersT1552.001
Credentials In FilesT1003.004
LSA SecretsT1055.013
Process DoppelgängingT1189
Drive-by CompromiseT1018
Remote System DiscoveryT1110.003
Password SprayingT1136.001
Local AccountT1059.007
JavaScriptT1114.002
Remote Email CollectionT1083
File and Directory Discovery
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Cyber Threat Intelligence (CTI) · explicit-idModule 3 — Core Frameworks Models
Cyber Threat Intelligence (CTI) · explicit-idModule 8 — Operationalizing CTI (CTI → Detection)
Cyber Threat Intelligence (CTI) · explicit-idMobile and Android vulnerability research
Vulnerability Research & Exploit Development · explicit-nameModule 9 — AI-assisted offensive security and MCP
Red Team & Offensive Security · topic-matchCryptography, secrets, and key lifecycle
Secure Code & Application Security · topic-matchPrivacy, secrets, confidential data, and model leakage
AI Security · topic-matchHuman, workload, pipeline, and emergency identity
Cloud Security · topic-matchContainer image, registry, runtime, and host security
Cloud Security · topic-matchAI-generated code, RAG, models, agents, and MCP-connected tools
Secure Code & Application Security · topic-matchAI incident response and forensic readiness
AI Security · topic-matchMemory-safety and low-level weakness classes
Vulnerability Research & Exploit Development · topic-match