RASPITE Targets Electric Utilities with Credential Theft and Remote Access
- Actor Motivations: Espionage,Undetected
- Attack Vectors: Credential stuffing,Backdoor,Spyware
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
Dragos identified RASPITE as a distinct activity group targeting electric utilities since at least early-to-mid 2017, with confirmed targeting in the US, Europe (including Saudi Arabia), and East Asia (including Japan). The group overlaps significantly with Symantec's LEAFMINER and uses identical initial access methodology to DYMALLOY and ALLANITE: compromising legitimate websites to embed hidden resource links that force visitors' browsers to initiate SMB connections, transmitting Windows NTLM credential hashes to attacker-controlled servers for offline cracking. Once credentials are obtained, RASPITE deploys install scripts for a malicious Windows service that beacons back to actor-controlled infrastructure, enabling remote access via RDP. The group spoofs domains for legitimate IT services to blend C2 traffic into normal network activity. While RASPITE's operations focus exclusively on IT networks within ICS-operating entities — particularly electric utilities — and it has not demonstrated ICS-specific or disruptive capabilities to date, Dragos assesses its targeting methodology and persistence as preparatory activity for potential future ICS operations. The group's focus on electric utility initial access operations mirrors the early stages seen before more impactful ICS attacks.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Energy None | Verified |
| Sector | Utilities | Verified |
| Region | Japan None | High |
| Region | United States | Verified |
| Region | Middle East Countries | Verified |
| Region | European Countries | Verified |
FAQs
Frequently Asked Questions about RASPITE's Targeting of Electric Utilities
RASPITE is a threat group tracked by Dragos that has been targeting electric utilities since at least 2017. The group compromises legitimate websites visited by utility employees and embeds hidden code that forces visitors' browsers to connect to attacker servers via SMB — transmitting Windows password hashes in the process. After cracking those hashes offline, RASPITE uses the stolen credentials to access victim networks, installs a persistent backdoor service, and maintains remote access via RDP. The group has been active across the US, Europe, the Middle East, and East Asia. While it hasn't demonstrated the ability to disrupt power systems directly, its focused targeting of electric utilities suggests it may be laying groundwork for future ICS attacks.
RASPITE is tracked by Dragos as a distinct activity group with significant overlap with Leafminer — a threat actor separately documented by Symantec and widely assessed to be Iran-based. Dragos does not make political attribution, focusing instead on behaviors and detections. The group shares methodology with other ICS-focused groups tracked by Dragos including DYMALLOY and ALLANITE, all of which use the same watering hole SMB credential harvesting technique.
RASPITE's current confirmed objectives are initial access and persistent presence on IT networks within electric utilities. The group collects credentials and maintains remote access, consistent with intelligence-gathering and pre-positioning goals. Critically, Dragos assesses this as preparatory activity — gaining the IT foothold that would be needed before any attempt to pivot toward operational technology (OT) or industrial control systems. No ICS-disruptive activity has been attributed to RASPITE to date, but the deliberate focus on electric utilities is a strong indicator of intent.
RASPITE operations have been confirmed across electric utilities in the United States, Europe (including Saudi Arabia), and East Asia (including Japan). While operations against US electric utilities are specifically documented, the group's broader targeting list spans multiple regions. The systematic, multi-year campaign against utilities across three continents indicates a well-resourced, persistent actor with global targeting scope within the electric sector.
The confirmed targets are electric utilities — organizations that generate, transmit, or distribute electrical power. This includes both investor-owned utilities and public power entities. The focus is specifically on companies that operate industrial control systems (ICS) for power grid management, making them high-value targets for adversaries seeking potential leverage over critical national infrastructure.
RASPITE uses a technique called strategic website compromise. The group identifies and compromises websites that electric utility employees are likely to visit — such as industry news sites, vendor portals, or professional resources. They then inject hidden code into those pages that silently forces any Windows visitor's browser to attempt an SMB file connection to an attacker-controlled server. This connection automatically transmits the user's Windows NTLM password hash, which RASPITE then cracks offline. With the stolen credentials, they can log into the victim's corporate network. They then install a persistent backdoor service on compromised machines that checks in regularly with their command-and-control servers, and use RDP to interactively access the systems remotely.
Electric utilities control the power grid — infrastructure that modern economies, military operations, hospitals, and civilian life all depend on. For a state-aligned adversary, gaining persistent access to electric utility IT networks provides multiple strategic advantages: intelligence on grid operations, the ability to understand vulnerabilities for potential future disruption, and pre-positioned access that could be activated during a geopolitical crisis. The 2015 and 2016 Ukraine power grid attacks demonstrated that compromising utility IT networks is the essential first step before any attempt to manipulate operational technology systems to cause outages.
Block all outbound SMB traffic at the network perimeter — this is the most direct defense against the credential harvesting technique RASPITE relies on. Enable SMB signing and consider disabling NTLM authentication on corporate networks to prevent hash capture even if SMB connections are initiated. Monitor for unexpected Windows service installations and for outbound connections from newly installed services. Implement strict network segmentation between IT and OT networks so that a compromised IT endpoint cannot be used as a stepping stone toward industrial control systems. Watch DNS and web traffic for connections to domains that closely mimic legitimate IT service providers — RASPITE spoofs these for C2. Electric utilities should treat any unauthorized remote access or service installation as a potential ICS-preparatory event and escalate accordingly.