Overview 7 indicators
Leafminer is an Iranian threat group that has targeted government organizations and business entities in the Middle East since at least early 2017.
| domain | 7 | G0077-domain.txt |
Techniques 17 ATT&CK
Open in ATT&CK Navigator → or download the layer (17 techniques, layer 4.5)
- T1003.001 LSASS Memory
- T1003.004 LSA Secrets
- T1003.005 Cached Domain Credentials
- T1018 Remote System Discovery
- T1027.010 Command Obfuscation
- T1046 Network Service Discovery
- T1055.013 Process Doppelgänging
- T1059.007 JavaScript
- T1083 File and Directory Discovery
- T1110.003 Password Spraying
- T1114.002 Remote Email Collection
- T1136.001 Local Account
- T1189 Drive-by Compromise
- T1552.001 Credentials In Files
- T1555 Credentials from Password Stores
- T1555.003 Credentials from Web Browsers
- T1588.002 Tool
Software 4
Principal sources 1 reports
Ranked by how many of this actor's indicators each report brought in.
Timeline 7 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
7 shown
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
symantec.com/blogs/threat-intelligence/leafminer-esp…
adobe-flash.us adobe-plugin.bid ilhost.in iqhost.us microsoft-office-free-templates-download.btc-int.in microsoft-office-free-templates.in offiice365.us