Threats Feed|RASPITE|Last Updated 30/04/2026|AuthorCertfa Radar|Publish Date30/05/2020

RASPITE Targets Electric Utilities with Credential Theft and Remote Access

  • Actor Motivations: Espionage,Undetected
  • Attack Vectors: Credential stuffing,Backdoor,Spyware
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Dragos identified RASPITE as a distinct activity group targeting electric utilities since at least early-to-mid 2017, with confirmed targeting in the US, Europe (including Saudi Arabia), and East Asia (including Japan). The group overlaps significantly with Symantec's LEAFMINER and uses identical initial access methodology to DYMALLOY and ALLANITE: compromising legitimate websites to embed hidden resource links that force visitors' browsers to initiate SMB connections, transmitting Windows NTLM credential hashes to attacker-controlled servers for offline cracking. Once credentials are obtained, RASPITE deploys install scripts for a malicious Windows service that beacons back to actor-controlled infrastructure, enabling remote access via RDP. The group spoofs domains for legitimate IT services to blend C2 traffic into normal network activity. While RASPITE's operations focus exclusively on IT networks within ICS-operating entities — particularly electric utilities — and it has not demonstrated ICS-specific or disruptive capabilities to date, Dragos assesses its targeting methodology and persistence as preparatory activity for potential future ICS operations. The group's focus on electric utility initial access operations mirrors the early stages seen before more impactful ICS attacks.

Detected Targets

TypeDescriptionConfidence
SectorEnergy
None
Verified
SectorUtilities
Verified
RegionJapan
None
High
RegionUnited States
Verified
RegionMiddle East Countries
Verified
RegionEuropean Countries
Verified

FAQs

Frequently Asked Questions about RASPITE's Targeting of Electric Utilities

RASPITE is a threat group tracked by Dragos that has been targeting electric utilities since at least 2017. The group compromises legitimate websites visited by utility employees and embeds hidden code that forces visitors' browsers to connect to attacker servers via SMB — transmitting Windows password hashes in the process. After cracking those hashes offline, RASPITE uses the stolen credentials to access victim networks, installs a persistent backdoor service, and maintains remote access via RDP. The group has been active across the US, Europe, the Middle East, and East Asia. While it hasn't demonstrated the ability to disrupt power systems directly, its focused targeting of electric utilities suggests it may be laying groundwork for future ICS attacks.

RASPITE is tracked by Dragos as a distinct activity group with significant overlap with Leafminer — a threat actor separately documented by Symantec and widely assessed to be Iran-based. Dragos does not make political attribution, focusing instead on behaviors and detections. The group shares methodology with other ICS-focused groups tracked by Dragos including DYMALLOY and ALLANITE, all of which use the same watering hole SMB credential harvesting technique.

RASPITE's current confirmed objectives are initial access and persistent presence on IT networks within electric utilities. The group collects credentials and maintains remote access, consistent with intelligence-gathering and pre-positioning goals. Critically, Dragos assesses this as preparatory activity — gaining the IT foothold that would be needed before any attempt to pivot toward operational technology (OT) or industrial control systems. No ICS-disruptive activity has been attributed to RASPITE to date, but the deliberate focus on electric utilities is a strong indicator of intent.

RASPITE operations have been confirmed across electric utilities in the United States, Europe (including Saudi Arabia), and East Asia (including Japan). While operations against US electric utilities are specifically documented, the group's broader targeting list spans multiple regions. The systematic, multi-year campaign against utilities across three continents indicates a well-resourced, persistent actor with global targeting scope within the electric sector.

The confirmed targets are electric utilities — organizations that generate, transmit, or distribute electrical power. This includes both investor-owned utilities and public power entities. The focus is specifically on companies that operate industrial control systems (ICS) for power grid management, making them high-value targets for adversaries seeking potential leverage over critical national infrastructure.

RASPITE uses a technique called strategic website compromise. The group identifies and compromises websites that electric utility employees are likely to visit — such as industry news sites, vendor portals, or professional resources. They then inject hidden code into those pages that silently forces any Windows visitor's browser to attempt an SMB file connection to an attacker-controlled server. This connection automatically transmits the user's Windows NTLM password hash, which RASPITE then cracks offline. With the stolen credentials, they can log into the victim's corporate network. They then install a persistent backdoor service on compromised machines that checks in regularly with their command-and-control servers, and use RDP to interactively access the systems remotely.

Electric utilities control the power grid — infrastructure that modern economies, military operations, hospitals, and civilian life all depend on. For a state-aligned adversary, gaining persistent access to electric utility IT networks provides multiple strategic advantages: intelligence on grid operations, the ability to understand vulnerabilities for potential future disruption, and pre-positioned access that could be activated during a geopolitical crisis. The 2015 and 2016 Ukraine power grid attacks demonstrated that compromising utility IT networks is the essential first step before any attempt to manipulate operational technology systems to cause outages.

Block all outbound SMB traffic at the network perimeter — this is the most direct defense against the credential harvesting technique RASPITE relies on. Enable SMB signing and consider disabling NTLM authentication on corporate networks to prevent hash capture even if SMB connections are initiated. Monitor for unexpected Windows service installations and for outbound connections from newly installed services. Implement strict network segmentation between IT and OT networks so that a compromised IT endpoint cannot be used as a stepping stone toward industrial control systems. Watch DNS and web traffic for connections to domains that closely mimic legitimate IT service providers — RASPITE spoofs these for C2. Electric utilities should treat any unauthorized remote access or service installation as a potential ICS-preparatory event and escalate accordingly.

About Affiliation
RASPITE
RASPITE is Dragos's designation for an Iranian-linked threat group active since at least 2017, focused on initial access operations against electric utility organizations in the United States, Europe, the Middle East, and East Asia. The group gains access through strategic website compromise (watering hole attacks) targeting websites of interest to utility sector personnel, embedding links that prompt SMB connections to harvest Windows credentials. After credential theft, RASPITE deploys scripts to install a malicious service providing remote access to compromised machines. Dragos assessed RASPITE maps closely to the Leafminer cluster tracked by Symantec, which documented the same underlying Iranian actor's broader targeting of government, energy, finance, and transportation sectors across the Middle East. While RASPITE's focus on ICS-operating entities is clear, the group had not demonstrated a destructive ICS-specific capability at time of reporting, indicating operations concentrated on initial access and intelligence collection as preparation for potential future actions against critical infrastructure.
View RASPITE's Insights