Hexane
Named by DragosSuspected state sponsor: Islamic Republic of IranHEXANE is Secureworks' designation for the Iranian threat cluster known as Lyceum. Active since at least 2018, the group targets oil and gas and telecommunications organizations in the Middle East and Africa using credential spraying, spear phishing, and custom malware including the DanBot remote access trojan. Secureworks first documented HEXANE in 2019, highlighting its focus on upstream energy companies and ISPs — a targeting profile consistent with Iranian state intelligence requirements for monitoring regional energy flows and communications infrastructure.
Targeted Regions
Middle EastMiddle East
May 2019 ~ Aug 2019
May 2019 ~ Aug 2019
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.