If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/groups/G0077 - Leafminer, Raspite, Group G007.

site address: attack.mitre.org/groups/G0077 redirected to: attack.mitre.org/groups/G0077

site title: Leafminer, Raspite, Group G0077 MITRE ATT&CK®

Our opinion (on Tuesday 18 August 2026 16:40:44 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:


page from cache: 1 minute ago
Meta tags:

Headings (most frequently used words):

leafminer, associated, group, descriptions, techniques, used, software, references, enterprise, layer,

Text of the page (most frequently used words):
leafminer (22), #enterprise (20), credentials (18), password (17), and (16), used (15), credential (14), dumping (12), from (12), att (11), the (10), all (10), tools (10), for (10), account (9), stores (8), lazagne (8), information (8), remote (6), tool (6), several (6), retrieving (6), login (6), including (6), ics (5), mobile (5), none (5), techniques (5), 2018 (5), domain (5), email (5), files (5), called (5), mitre (4), use (4), software (4), groups (4), raspite (4), security (4), system (4), windows (4), process (4), tickets (4), collection (4), discovery (4), mailsniper (4), has (4), search (4), version (4), 2026 (3), campaigns (3), cti (3), data (3), defenses (3), service (3), services (3), create (3), ticket (3), authentication (3), unsecured (3), steal (3), forge (3), lsa (3), secrets (3), lsass (3), memory (3), manager (3), web (3), browsers (3), mimikatz (3), spraying (3), name (3), 001 (3), victim (3), group (3), corporation (2), are (2), domains (2), resources (2), reference (2), components (2), analytics (2), detection (2), strategies (2), assets (2), mitigations (2), tactics (2), matrices (2), core (2), objects (2), august (2), retrieved (2), july (2), middle (2), references (2), execution (2), smb (2), psexec (2), pass (2), alternate (2), material (2), kerberos (2), manipulation (2), history (2), injection (2), access (2), brute (2), force (2), cached (2), etc (2), about (2), systems (2), doppelgänging (2), 002 (2), obfuscated (2), that (2), command (2), network (2), infected (2), victims (2), using (2), 003 (2), javascript (2), associated (2), october (2), g0077 (2), ckcon (2), person (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, sub, dragos, inc, november, symantec, response, new, espionage, targeting, eastern, regions, admin, shares, lateral, transfer, modify, s0029, hash, private, keys, silver, golden, certificates, rogue, controller, dcsync, support, provider, boot, logon, autostart, sid, token, s0002, s0413, proc, filesystem, passwd, shadow, keychain, s0349, t1552, microsoft, sysinternals, gather, detailed, t1018, evade, while, deploying, compromised, 013, t1055, 005, 004, t1003, obtained, such, obtain, capabilities, t1588, scripts, were, machines, obfuscation, 010, t1027, scanned, vulnerabilities, t1046, desktop, another, utility, sobolsoft, extract, attachments, eml, file, directory, t1083, through, exchange, server, mailboxes, keywords, t1114, watering, holes, drive, compromise, t1189, t1555, imecab, set, persistent, machine, local, t1136, code, scripting, interpreter, 007, t1059, total, bruteforcer, perform, internal, t1110, view, download, layer, navigator, layers, description, descriptions, live, permalink, last, modified, created, iranian, threat, targeted, government, organizations, business, entities, east, since, least, early, 2017, home, open, join, mclean, hotel, location, details, can, found, register, here, blog, contribute, benefactors, legal, branding, updates, engage, with, advisory, council, learn, more, get, started, detections,


Text of the page (random words):
leafminer raspite group g0077 mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home groups leafminer leafminer leafminer is an iranian threat group that has targeted government organizations and business entities in the middle east since at least early 2017 1 id g0077 ⓘ associated groups raspite version 2 4 created 17 october 2018 last modified 31 july 2026 version permalink live version associated group descriptions name description raspite 2 att ck navigator layers enterprise layer download view techniques used domain id name use enterprise t1110 003 brute force password spraying leafminer used a tool called total smb bruteforcer to perform internal password spraying 1 enterprise t1059 007 command and scripting interpreter javascript leafminer infected victims using javascript code 1 enterprise t1136 001 create account local account leafminer used a tool called imecab to set up a persistent remote access account on the victim machine 1 enterprise t1555 credentials from password stores leafminer used several tools for retrieving login and password information including lazagne 1 003 credentials from web browsers leafminer used several tools for retrieving login and password information including lazagne 1 enterprise t1189 drive by compromise leafminer has infected victims using watering holes 1 enterprise t1114 002 email collection remote email collection leafminer used a tool called mailsniper to search through the exchange server mailboxes for keywords 1 enterprise t1083 file and directory discovery leafminer used a tool called mailsniper to search for files on the desktop and another utility called sobolsoft to extract attachments from eml files 1 enterprise t1046 network service discovery leafminer scanned network services to search for vulnerabilities in the victim system 1 enterprise t1027 010 obfuscated files or information command obfuscation leafminer obfuscated scripts that were used on victim machines 1 enterprise t1588 002 obtain capabilities tool leafminer has obtained and used tools such as lazagne mimikatz psexec and mailsniper 1 enterprise t1003 001 os credential dumping lsass memory leafminer used several tools for retrieving login and password information including lazagne and mimikatz 1 004 os credential dumping lsa secrets leafminer used several tools for retrieving login and password information including lazagne 1 005 os credential dumping cached domain credentials leafminer used several tools for retrieving login and password information including lazagne 1 enterprise t1055 013 process injection process doppelgänging leafminer has used process doppelgänging to evade security software while deploying tools on compromised systems 1 enterprise t1018 remote system discovery leafminer used microsoft s sysinternals tools to gather detailed information about remote systems 1 enterprise t1552 001 unsecured credentials credentials in files leafminer used several tools for retrieving login and password information including lazagne 1 software id name references techniques s0349 lazagne 1 credentials from password stores windows credential manager credentials from password stores credentials from web browsers credentials from password stores credentials from password stores keychain os credential dumping lsa secrets os credential dumping etc passwd and etc shadow os credential dumping lsass memory os credential dumping cached domain credentials os credential dumping proc filesystem unsecured credentials credentials in files s0413 mailsniper 1 account discovery email account brute force password spraying email collection remote email collection s0002 mimikatz 1 access token manipulation sid history injection account manipulation boot or logon autostart execution security support provider credentials from password stores credentials from password stores credentials from web browsers credentials from password stores windows credential manager os credential dumping security account manager os credential dumping lsass memory os credential dumping lsa secrets os credential dumping dcsync rogue domain controller steal or forge authentication certificates steal or forge kerberos tickets golden ticket steal or forge kerberos tickets silver ticket unsecured credentials private keys use alternate authentication material pass the hash use alternate authentication material pass the ticket s0029 psexec 1 create account domain account create or modify system process windows service lateral tool transfer remote services smb windows admin shares system services service execution references symantec security response 2018 july 25 leafminer new espionage campaigns targeting middle eastern regions retrieved august 28 2018 dragos inc 2018 august 2 raspite retrieved november 26 2018 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Images from subpage: "attack.mitre.org/matrices/" Verify
Images from subpage: "attack.mitre.org/matrices/enterprise/" Verify
Images from subpage: "attack.mitre.org/matrices/mobile/" Verify
Images from subpage: "attack.mitre.org/matrices/ics/" Verify
Images from subpage: "attack.mitre.org/tactics/" Verify

Verified site has: 103 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-80 81-85 86-90 91-95 96-100
101-103


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/groups/G0077/
access-control-allow-origin *
expires Tue, 18 Aug 2026 16:49:15 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 6FD2:25E3D2:49C9B8:4D4AA6:6A848AB2
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Tue, 18 Aug 2026 16:39:15 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630049-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787071155.205646,VS0,VE85
vary Accept-Encoding
x-fastly-request-id b9a6d009b736fc33acae04080181018c2ffb32d6
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:04 GMT
access-control-allow-origin *
etag W/ 6a75ea84-102df
expires Tue, 18 Aug 2026 16:49:15 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 40F2:362F68:49C91A:4D4A94:6A848AB3
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Tue, 18 Aug 2026 16:39:15 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630049-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787071155.299353,VS0,VE87
vary Accept-Encoding
x-fastly-request-id 8b68f518dd4e6f6d8952049cdb51144a5472631e
content-length 8720

Meta Tags

title="Leafminer, Raspite, Group G0077 | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size66271
load time (s)0.423581
redirect count1
speed download20614
server IP 185.199.110.153
* all occurrences of the string "http://" have been changed to "htt???/"