Actors Insights|Latest update04/07/2026

Hexane

Named by DragosSuspected state sponsor: Islamic Republic of Iran

HEXANE is Secureworks' designation for the Iranian threat cluster known as Lyceum. Active since at least 2018, the group targets oil and gas and telecommunications organizations in the Middle East and Africa using credential spraying, spear phishing, and custom malware including the DanBot remote access trojan. Secureworks first documented HEXANE in 2019, highlighting its focus on upstream energy companies and ISPs — a targeting profile consistent with Iranian state intelligence requirements for monitoring regional energy flows and communications infrastructure.

First Seen:Apr 2018
Last Seen:Oct 2021
Indexed Reports:2
Public IOCs:0
Cluster: LyceumMitre: HEXANEMisp: LYCEUM
also known as:
COBALT LYCEUM (SecureWorks)Hexane (Dragos)UNC1530 (Mandiant)SpirlinMYSTICDOMESiameseKitten (ClearSky)Chrono Kitten (CrowdStrike)Storm-0133 (Microsoft)COBALT LYCEUM (SecureWorks)G1001 (Mitre)

Targeted Regions

Middle East
ME
Middle East
Middle East
May 2019 ~ Aug 2019
May 2019 ~ Aug 2019
Jan 2018Aug 2026

Targeted Sectors

Information TechnologyOil and GasTelecommunication

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.