ATT&CKGroupsLeafminer

Leafminer

G0077

Threat group.View on attack.mitre.org

About this group

Leafminer is an Iranian threat group that has targeted government organizations and business entities in the Middle East since at least early 2017.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1003.001
LSASS Memory

Leafminer used several tools for retrieving login and password information, including LaZagne and Mimikatz.

T1003.004
LSA Secrets

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1003.005
Cached Domain Credentials

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1018
Remote System Discovery

Leafminer used Microsoft’s Sysinternals tools to gather detailed information about remote systems.

T1027.010
Command Obfuscation

Leafminer obfuscated scripts that were used on victim machines.

T1046
Network Service Discovery

Leafminer scanned network services to search for vulnerabilities in the victim system.

T1055.013
Process Doppelgänging

Leafminer has used Process Doppelgänging to evade security software while deploying tools on compromised systems.

T1059.007
JavaScript

Leafminer infected victims using JavaScript code.

T1083
File and Directory Discovery

Leafminer used a tool called MailSniper to search for files on the desktop and another utility called Sobolsoft to extract attachments from EML files.

T1110.003
Password Spraying

Leafminer used a tool called Total SMB BruteForcer to perform internal password spraying.

T1114.002
Remote Email Collection

Leafminer used a tool called MailSniper to search through the Exchange server mailboxes for keywords.

T1136.001
Local Account

Leafminer used a tool called Imecab to set up a persistent remote access account on the victim machine.

T1189
Drive-by Compromise

Leafminer has infected victims using watering holes.

T1552.001
Credentials In Files

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1555
Credentials from Password Stores

Leafminer used several tools for retrieving login and password information, including LaZagne.

View all 17 procedure examples

Software4

Campaigns0

None recorded.

References1

  1. Symantec Leafminer July 2018 Open source
    Symantec Security Response. (2018, July 25). Leafminer: New Espionage Campaigns Targeting Middle Eastern Regions. Retrieved August 28, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.