Actors Insights|Latest update04/07/2026

SiameseKitten

Named by ClearSkySuspected state sponsor: Islamic Republic of Iran

SiameseKitten is an Israeli cybersecurity researchers' designation for the Iranian threat cluster known as Lyceum and HEXANE. Active since at least 2021, the group targets telecommunications and technology companies in Israel and the broader Middle East, deploying custom backdoors including Shark and Milan alongside updated versions of the DanBot toolset. SiameseKitten activity represents a continued evolution of the Lyceum cluster's capabilities and targeting, with a growing focus on Israeli infrastructure consistent with Iranian state adversarial priorities in the region.

First Seen:May 2021
Last Seen:Jun 2022
Indexed Reports:1
Public IOCs:29
Cluster: LyceumMitre: HEXANEMisp: LYCEUM
also known as:
COBALT LYCEUM (SecureWorks)Hexane (Dragos)UNC1530 (Mandiant)SpirlinMYSTICDOMESiameseKitten (ClearSky)Chrono Kitten (CrowdStrike)Storm-0133 (Microsoft)COBALT LYCEUM (SecureWorks)G1001 (Mitre)

Targeted Regions

Israel
IL
Israel
Israel
May 2021 ~ Aug 2021
May 2021 ~ Aug 2021
Middle East
ME
Middle East
Middle East
May 2021 ~ Aug 2021
May 2021 ~ Aug 2021
Jan 2021Oct 2026

Targeted Sectors

Information TechnologyOil and Gas

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.