All actors

Leafminer

Also reported as Raspite, Flash Kitten, RASPITE and LeafMiner. Linked to Iran by one source.

Reports
16
Last reported
Known CVEs
11
Techniques in ATT&CK
17
Origin
Iran
ID
G0077
Merge evidence
8 alias matches

Reports per quarter

  1. 2018 Q3: 4 reports
  2. 2018 Q4: no reports
  3. 2019 Q1: 3 reports
  4. 2019 Q2: no reports
  5. 2019 Q3: 1 report
  6. 2019 Q4: 2 reports
  7. 2020 Q1: 3 reports
  8. 2020 Q2: no reports
  9. 2020 Q3: no reports
  10. 2020 Q4: no reports
  11. 2021 Q1: no reports
  12. 2021 Q2: no reports
  13. 2021 Q3: no reports
  14. 2021 Q4: no reports
  15. 2022 Q1: 1 report
  16. 2022 Q2: no reports
  17. 2022 Q3: no reports
  18. 2022 Q4: no reports
  19. 2023 Q1: no reports
  20. 2023 Q2: no reports
  21. 2023 Q3: no reports
  22. 2023 Q4: no reports
  23. 2024 Q1: no reports
  24. 2024 Q2: no reports
  25. 2024 Q3: no reports
  26. 2024 Q4: no reports
  27. 2025 Q1: no reports
  28. 2025 Q2: no reports
  29. 2025 Q3: no reports
  30. 2025 Q4: no reports
  31. 2026 Q1: no reports
  32. 2026 Q2: 2 reports
Dated reports, 2018 Q3 to 2026 Q2.

Techniques in ATT&CK

Listed by ATT&CK

Show all 17 techniques Show fewer

No report from the last two years names a technique ID.

CVEs named in reports

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. Current Iran-Associated Cyber Threats

    file creation date Symantec fromORKL

  2. North American Electric Cyber Threat Perspective

    Malpedia library date fromORKL

  3. Group-IB_Hi-Tech_Crime_Trends_2019-2020_en

    file creation date fromORKL

  4. Group-IB_Hi-Tech_Crime_Trends_2019-2020

    date in the CCS '25 data Group-IB fromORKLCCS '25 data

  5. Report2019GlobalThreatReport

    file creation date fromORKL

Show all 16 reports Show fewer

Newest first. Details opens the report in Explore.