Threats Feed|Leafminer|Last Updated 30/04/2026|AuthorCertfa Radar|Publish Date25/07/2018

Leafminer Cyber Espionage Campaign Targets Middle Eastern Governments

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Vulnerability Exploitation,Backdoor,Spyware
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Symantec's July 2018 report exposed Leafminer, an Iran-based threat actor active since at least early 2017, targeting government organizations and multiple business sectors across the Middle East — including Saudi Arabia, the UAE, Qatar, Kuwait, Bahrain, Egypt, Israel, and Afghanistan. Symantec identified a critical operational security failure: Leafminer left a staging server publicly accessible, exposing their entire toolkit of 112 files including custom malware, exploitation frameworks, and reconnaissance logs. The group used three main intrusion methods: watering hole attacks that planted JavaScript to harvest SMB/NTLM credential hashes from visitors' browsers; vulnerability scanning and exploitation using the EternalBlue exploit (CVE-2017-0144/MS17-010) from the leaked Fuzzbunch framework for lateral movement; and dictionary/brute-force attacks against Exchange and RDP logins using THC Hydra and Total SMB BruteForcer. Custom malware included Backdoor.Sorgu (remote access) and Trojan.Imecab (persistent guest account creation). For credential dumping, the group deployed OrangeTeghal — a rebranded Mimikatz — using Process Doppelgänging to evade detection. Post-compromise tools included MailSniper, LaZagne, PsExec, HoboCopy, and SQL backup recovery utilities. Leafminer also scanned for Heartbleed (CVE-2014-0160). A target list written in Farsi containing 809 organizations was recovered from the staging server, grouping targets by geography and industry sector.

Detected Targets

TypeDescriptionConfidence
SectorConstruction
Verified
SectorFinancial
Verified
SectorFood and Agriculture
Verified
SectorGovernment Agencies and Services
Verified
SectorAerospace
Verified
SectorEnergy
Verified
SectorTelecommunication
Verified
SectorTransportation
Verified
SectorUtilities
Verified
RegionAfghanistan
Verified
RegionAzerbaijan
Verified
RegionBahrain
Verified
RegionEgypt
Verified
RegionIsrael
Verified
RegionKuwait
Verified
RegionLebanon
Verified
RegionQatar
Verified
RegionSaudi Arabia
Verified
RegionUnited Arab Emirates
Verified

Extracted IOCs

  • adobe-flash[.]us
  • adobe-plugin[.]bid
  • ilhost[.]in
  • iqhost[.]us
  • microsoft-office-free-templates[.]in
  • offiice365[.]us
  • microsoft-office-free-templates-download.btc-int[.]in
  • 09653415084e64caed272f089610c5218a60372e17755ba71176785736e71c0d
  • 09a20ca2db5b75f4ee55874929dec64acfffa46d54a4ed561b9c3f04baa91d52
  • 1e4f56a1999ffa5376ef0acaaa5da0993f07e9c5aa1c222e297db7a4117d04b1
  • 200ec4e8f16ed205cf94c02fcd73ee43ee511fa44ce34c458a1fca195c4bc737
  • 2591b50355ed8053c8ed2e122f0b5769dd52c6d0b658cd0f2847f39056c6ac8c
  • 332762804dd17f9b81620ea60ca8962daa493df24f6d98799d784d50fd4d0108
  • 3373d81a74c1ea75c794244b2c6d4e5fb246224128412b9348291e2f68994d83
  • 36e9c95b65692b110f4fe2ed27aa6066368c07525c020ec081b59bad272e6172
  • 48529fc232a99b8cfa14cdc1b982615e9a96942b4e0a79e4a88d504faac74c7c
  • 4b16cb8b0eaeb8449d35290edb00beb3002852ad0225f52e5476e16c853447c5
  • 58c9e11a2cd18bc6762753b27225423257b0d8e84592a7fe8b1c9bdd97129546
  • 670dc0a8182503b272f8a0f5cf93ea1e9f12fd46afdf4930249bc0fa588bac2d
  • 6f5b1269175d3937a5f92c62ff3ef1dd693827705d0d41456d93d5243c1dbaad
  • 70c30b4cc6a9a420bec3ad25a0147c7ff91535a04ece95036334cb23044eda4e
  • 7897406109e2454e4d99044e24a2d4fe5902473c2c76b82c2569336805989482
  • 7b06957c6b8450953967eb9c5f762e389a92fcf761b6885b7cb6dd2407641f3a
  • 7b8d27bfd5f2199e984c3038ce7625069f9ee0ec57dbfd7998e37afbe18011f3
  • 7d829abe26b30ced467513e95f3448bc9f30de2fdced81c20b0d7699bd69c644
  • 84803151c5b73a53de91844968f377e6ee33ba82910aa1f612595a19aeb7e529
  • 85e9b5c3bd88a0c2b535c8d89ed0e9f875895e758228da16b5a46f6ff70e7e77
  • 9aa8f2d9245d0e6cef375ed999da6a3c9715fbe2a20589fdb388a8687707133a
  • 9d3801af7f8270ee550f0e3bb31e2ead903c45849e099c80d3c34b0076ca7e6f
  • a115a2a704386293f4c5e7108b9dab6afc42d4647cbff47023f2d2039c6b72ae
  • a2155e4dd281ef7b01a1490943b7fb06706d7ef02c0f955611e941d06b6e3ccf
  • a36fc0d9cb5b415fa8d6fe89434aca931bc4d0f9ac56ada7b7b9a9e601966860
  • a4ec0964b115cdc7c3e2fd2bd60651a5105981485a4cd9a1ce5e3d29222f6303
  • ac33d303a9903f8a181e323eff6f0053234546e9b963f6bd1a2867bbb70ce2f9
  • b13ce2692d7ea4ebf343916d1f4c6de8a73376d486d96f3e7ceddecab5068ccf
  • c05205771d1cb9bfbfd7139a7ec8f8364c2820d6de3bbb93806530f1dc7a4283
  • c402e570ea5e69c42898cb6a1a6be39fa9f5a90e909c2d1a4a2276df80abca97
  • caa2bd3596cf15d4d09fad3d110052460bc05933587a16e13f879fe1469a1377
  • cb34a8f0dacb1ddccd89e0f40822dbdb0a3e32bb22c0801325be53bff55afd85
  • d01f01cc4832786c2821bb51d1abf40efbdf5127cd1d11e674c76996f1f1b145
  • d152da24739964acc8cc9fbd8f60a8ae7b8f7903c37168ce53e01b451d4aba5d
  • d1e4081b5fdeb09b280674e0c34f5495527a621bb4f42601f97f123761c514c0
  • d1ee0cf551e5fc37d482484d3de1c5718a5b8c9cfadd907b7b3ccf9324a599fe
  • d94c5bd51cdbdd87ee4eb8005022be2ed763c791660416212a8e6a6b18576ac8
  • de481b765df8a44dc7b8528bf4822332cbd6105bce780e3c99da2cc67ab1263b
  • e3612f7e389695f6f4184cbdc5dc9512e370f3f3863afcb38a17d59d6ead8dc0
  • e8f409387c6df73c201776633d44ac97d4fc1958bf79b1b36659e4bf904ccf28
  • e931848dd6e5914e8ed0b287ef27544bf6c444fae05590a174307b437a1ea866
  • ebd01e75c633c212265fe883e869b543b27c34819d8501a52dbd21fc2cb533fc
  • efb340cf61009acc14b8463c185340bae0269b957143469dc7270af85ee2092d
  • f67d378140f4aca98d4bd427eda7052ad1205dab8b6028a7fa00254d0c60aeea
  • fd026f5f3995b0664cde644da0d21b7488f5baabe0467dcec14092624b86b900
  • ff8c9d8c6f16a466d8e598c25829ec0c2fb4503b74d17f307e13c28fd2e99b93
  • ffb6acd2715dd988fe3c3fdbd7d45159f8e5b529eea506a856109a8696e93a80
  • 188[.]165.187.235
  • 51[.]254.173.240
  • 188[.]165.187.235/file[.]gif
  • 51[.]254.173.240/file[.]gif
  • adobe-plugin[.]bid/file.gif
download

Tip: 59 related IOCs (2 IP, 7 domain, 3 URL, 0 email, 47 file hash) to this threat have been found.

FAQs

Frequently Asked Questions about Leafminer's Middle East Espionage Campaign

Between 2017 and 2018, an Iran-based threat group called Leafminer ran a broad espionage campaign against government bodies and businesses across the Middle East. The group used a mix of techniques to break into targets — watering hole websites, known software vulnerabilities, and brute-force password attacks — then deployed custom malware and off-the-shelf hacking tools to steal email data, files, and database contents. Symantec uncovered the campaign after Leafminer made a significant mistake: they left a staging server publicly accessible, exposing their entire toolkit, operations logs, and a Farsi-language list of 809 target organizations.

The attacks were carried out by Leafminer, a threat actor assessed by Symantec to be based in Iran. Clues pointing to Iranian origin include the Farsi-language target list, references to the Iranian hacking forum Ashiyane in the web shell code, and connections to the Iranian hacker group Sun Army through the malware developer alias "MagicCoder." The group is considered a relatively newer entrant with significant ambition but uneven tradecraft — they adopted advanced techniques quickly but made basic operational security mistakes that exposed their entire operation.

The primary goals were intelligence collection and data exfiltration. After gaining access to target networks, Leafminer focused on stealing email data (using MailSniper to search Exchange servers), documents and files (using indexing and file-copying tools), and database contents. The recovered target list — with 809 organizations grouped by industry and country, all written in Farsi — confirms this was a systematic intelligence-gathering operation directed at a broad range of regional strategic and economic targets.

The campaign was broad in geographic and sectoral scope. Symantec confirmed active malware infections on 44 systems across four Middle Eastern regions, with targeted countries including Saudi Arabia, the UAE, Qatar, Kuwait, Bahrain, Egypt, Israel, Lebanon, Azerbaijan, and Afghanistan. The recovered 809-target list spanned government agencies, finance, energy, aerospace, transportation, construction, telecommunications, food and agriculture, and utilities — indicating Leafminer was targeting critical national infrastructure and key economic sectors across the region.

Leafminer targeted government organizations across the Middle East as a primary focus, alongside sectors including finance, energy, aerospace, transportation, construction, telecommunications, food and agriculture, and utilities. The Farsi-language target list organized victims by both geography and industry, suggesting the group was operating with specific intelligence collection mandates across strategic sectors of regional economies — likely reflecting Iranian government intelligence priorities in the region.

Leafminer used three main methods to break into target networks. First, they compromised legitimate websites in the region and planted hidden JavaScript code that tricked visitors' browsers into making SMB requests, which transmitted the user's NTLM password hash to the attacker — who could then crack it offline. Second, they exploited the EternalBlue vulnerability (CVE-2017-0144), a severe Windows SMB flaw originally developed by the NSA and leaked in 2017, to move laterally within networks. Third, they ran brute-force and dictionary attacks against exposed Exchange email and RDP remote desktop login services. Once inside, they used a suite of tools to dump credentials, collect emails, copy files, and establish persistent backdoors.

Middle Eastern governments and critical infrastructure operators hold sensitive intelligence about regional security dynamics, economic resources, and foreign policy — all of direct strategic interest to Iran. Saudi Arabia, the UAE, and other Gulf states are longstanding geopolitical rivals of Iran, making their government communications and economic infrastructure high-value espionage targets. The breadth of sectoral targeting — covering energy, finance, transportation, and telecommunications — also suggests an interest in mapping the economic infrastructure of adversary states, which has both intelligence and potential sabotage value.

Patch MS17-010 (EternalBlue) immediately on all Windows systems if not already done, and block inbound SMB traffic on network perimeters. Filter outbound SMB traffic to prevent browsers from making external SMB connections — this stops the NTLM hash theft technique used by Leafminer's watering holes. Enforce strong, unique passwords and multi-factor authentication on Exchange and RDP services to defeat dictionary attacks. Monitor for new local user account creation, Windows services installed with unusual names, and signs of Mimikatz or credential dumping activity. Regularly audit internet-facing servers and ensure staging or development servers are not publicly accessible. Deploy detection for Process Doppelgänging and similar fileless execution techniques on endpoints.

About Affiliation
Leafminer
Leafminer is Symantec's designation for an Iranian cyber espionage group active since at least 2017, also tracked as RASPITE by Dragos. The group targets government, energy, financial, transportation, and shipping organizations across the Middle East, with documented victims in Saudi Arabia, the UAE, Qatar, Kuwait, Bahrain, Egypt, Israel, and Afghanistan. Symantec's investigation uncovered a Farsi-language list of 809 target organizations compiled by the group, grouped by geography and industry, providing rare visibility into Iranian APT targeting priorities. Leafminer gains initial access through watering hole attacks and spear phishing, using a mix of publicly available tools alongside custom malware. Dragos's RASPITE research identified the same actor targeting US electric utility organizations, making Leafminer/RASPITE one of the first documented Iranian groups to focus on ICS-operating entities — though without demonstrated destructive ICS capability at time of reporting. The group's Iranian origin was assessed based on Farsi-language artifacts and targeting patterns consistent with Iranian state espionage priorities.
View Leafminer's Insights