Latest Update27/08/2026

Threats Feed

  1. Public

    Iranian Lyceum Group Deploys Malware Disguised as Adobe Update

    The Iranian SiameseKitten (Lyceum) group deployed new malware masquerading as an Adobe update, communicating with a command and control server. The malware includes a reverse shell and employs fake Microsoft certificates, echoing tactics seen with other Iranian groups like Phosphorus. The attack involved a lure PDF related to drone attacks in Iran, aiming to establish persistence via the Startup folder. The parent file and reverse shell were downloaded from domains registered on June 6th, highlighting the group's continued use of sophisticated detection avoidance techniques.

    read more about Iranian Lyceum Group Deploys Malware Disguised as Adobe Update
  2. Public

    Lyceum Group Unveils Stealthy .NET DNS Backdoor in Middle East Campaign

    Zscaler ThreatLabz's June 2022 report documents a new Lyceum Group campaign deploying a .NET-based DNS backdoor named DnsSystem — a customized version of the open-source DIG.net tool — against targets in the Middle East. The malware was delivered via a macro-enabled Microsoft Word document disguised as a news report related to Iranian military affairs, with C2 infrastructure at news-spot.live (85.206.175.199). The document dropped and executed the DnsSystem backdoor, which uses DNS Hijacking for command-and-control: it communicates with the attacker by sending queries to a malicious DNS server and parsing TXT and A record responses for commands. Supported functions include remote command execution, file upload to and download from the C2 server, process and application window discovery, network configuration discovery, and security tool detection. Persistence is achieved by dropping the backdoor binary into the Windows Startup folder. C2 traffic is Base64-encoded. IOCs include 1 IP address (85.206.175.199), 2 domains (news-spot.live, cyberclub.one), 5 URLs, and 2 file hashes. IOC overlap with a concurrent Lyceum campaign (Check Point, March 2022) confirms the same actor and infrastructure.

    read more about Lyceum Group Unveils Stealthy .NET DNS Backdoor in Middle East Campaign
  3. Public

    Lyceum's Multi-Dropper Cyber Attack Targets Israeli and Saudi Entities

    Check Point Research's March 2022 report documents a Lyceum APT campaign that exploited the Russia-Ukraine war as a lure to target Israeli energy companies and entities in Saudi Arabia. In mid-March 2022, an Israeli energy organization received a spearphishing email from inews-reporter@protonmail[.]com with the subject "Russian war crimes in Ukraine," containing a link to a malicious document on news-spot[.]live hosting a Guardian article as a decoy. The campaign deployed three categories of executable droppers — a .NET DNS dropper, a .NET TCP dropper, and a Golang dropper — each delivering a different backdoor. The .NET DNS backdoor is a modified version of the DnsDig tool using the Heijden.DNS open-source library for DNS tunneling, supporting file upload/download and command execution. The .NET TCP backdoor communicates over raw TCP sockets with a configurable protocol, supporting command execution, screenshots, file listing, installed applications enumeration, and file upload/download/execution. The Golang HTTP backdoor operates in three stages (connectivity check, victim registration, command retrieval) using HTTP POST requests to /GO/1.php, /GO/2.php, and /GO/3.php. All droppers display a decoy PDF (Russia-Ukraine war related or Iranian cyber threat report) while silently downloading and executing the payload. Persistence is achieved via Startup folder placement or scheduled tasks. Attribution indicators include use of Heijden.DNS, DNS tunneling C2, infrastructure overlap with known Lyceum servers on the same ASN, and Protonmail registration addresses.

    read more about Lyceum's Multi-Dropper Cyber Attack Targets Israeli and Saudi Entities
  4. Public

    Lyceum's Cyber Espionage Campaign Targets Telecoms and ISPs in the Middle East and Africa

    Prevailion and Accenture's November 2021 joint report documents Lyceum (also known as HEXANE or Spirlin) targeting telecommunications providers and ISPs in Israel, Morocco, Tunisia, and Saudi Arabia, as well as a Ministry of Foreign Affairs in an unnamed African country. The campaign ran from at least July 2021 through November 2021. Lyceum deployed two updated malware families: Shark, a C#/.NET backdoor using HTTPS for C2 communication, and Milan, a Visual C++/.NET backdoor using DNS tunneling. Both support command execution, file upload and download, and system reconnaissance. Persistence is achieved via Windows scheduled tasks. XOR encoding is used to obfuscate C2 traffic. The group registered 26 C2 domains with security and Windows-update-themed naming patterns (e.g. defenderlive.com, dnsstatus.org, wsuslink.com, windowsupdatecdn.com). Two file hashes for Shark samples are documented. IOC overlap with earlier Lyceum campaigns confirms continuity of tooling and infrastructure across the group's operations from 2019 to 2021.

    read more about Lyceum's Cyber Espionage Campaign Targets Telecoms and ISPs in the Middle East and Africa
  5. Public

    Lyceum Intensifies Cyber Espionage on Tunisian Telecom and Aviation Sectors

    The Lyceum group (also known as Hexane) is a cyber threat actor focused on the telecommunications, energy and aviation sectors, particularly targeting high-profile organisations in Tunisia. Active since 2018, Lyceum has recently replaced its .NET-based malware with new C++ backdoors and PowerShell scripts to evade detection. The group continues to rely on DNS tunneling for command and control (C2) and uses tools for system reconnaissance, credential theft and keylogging. Lyceum also uses spoofed domains to disguise its activities, demonstrating an adaptive approach to persistent targeting of critical infrastructure.

    read more about Lyceum Intensifies Cyber Espionage on Tunisian Telecom and Aviation Sectors
  6. Public

    Lyceum Intensifies Cyber Espionage on Tunisian Telecom and Aviation Sectors

    The Lyceum group (also known as Hexane) is a cyber threat actor focused on the telecommunications, energy and aviation sectors, particularly targeting high-profile organisations in Tunisia. Active since 2018, Lyceum has recently replaced its .NET-based malware with new C++ backdoors and PowerShell scripts to evade detection. The group continues to rely on DNS tunneling for command and control (C2) and uses tools for system reconnaissance, credential theft and keylogging. Lyceum also uses spoofed domains to disguise its activities, demonstrating an adaptive approach to persistent targeting of critical infrastructure.

    read more about Lyceum Intensifies Cyber Espionage on Tunisian Telecom and Aviation Sectors
  7. Public

    Siamesekitten APT Targets Israeli IT Firms with Supply Chain Attacks

    The Iranian APT group Siamesekitten (Lyceum/Hexane) launched targeted cyberattacks on Israeli IT and technology firms in 2021 using advanced social engineering and supply chain tactics. The campaign impersonated HR personnel and organizations via phishing websites and LinkedIn profiles to distribute malware such as Milan and its successor Shark. Victims were infected with DanBot RAT through DNS tunneling and HTTPS C2 communication. The group also exploited legitimate tools like UltraVNC for remote access. Known for prior attacks on oil, gas, and telecom sectors in the Middle East and Africa, Siamesekitten’s recent focus highlights its shift to Israeli targets for espionage and data theft.

    read more about Siamesekitten APT Targets Israeli IT Firms with Supply Chain Attacks
  8. Public

    Lyceum APT Targets Middle Eastern Oil, Gas, and Telecom Sectors

    The Lyceum APT targets the oil, gas and telecommunications sectors in the Middle East, focusing on credential theft and network infiltration through a multi-stage attack chain. The initial infection involves malicious Microsoft Office documents that deploy DanDrop, a VBA-based malware dropper that installs DanBot, a remote access Trojan used for ongoing control. The group also uses PowerShell scripts, including keyloggers and credential decryption tools, to gather sensitive data from Active Directory and RDCMan configurations. The sophisticated attack chain used by this cybercrime group highlights the ongoing threat to critical infrastructure in the Middle East.

    read more about Lyceum APT Targets Middle Eastern Oil, Gas, and Telecom Sectors
  9. Public

    LYCEUM's Multi-Faceted DanBot Malware Targets Oil and Gas Sector

    CyberX Labs' January 2020 deep-dive analyzes DanBot, the primary Remote Access Trojan used by LYCEUM (HEXANE) against oil and gas sector targets in the Middle East. The report documents DanBot's multi-channel C2 architecture: it uses both DNS tunneling — built on a repurposed and renamed version of the Heijden.Dns open-source library — and HTTP/S communication. DanBot is delivered via spearphishing emails containing malicious XLS files with embedded VBA macros (DanDrop). The malware stores its configuration in encrypted files on disk and achieves persistence via Windows scheduled tasks. It supports both file download and file upload, and uses IPv4 and IPv6 addressing for C2 connectivity. C2 traffic is encoded using Base64 and symmetric encryption. The group also uses proxy infrastructure to mask attacker origins. DanBot variants appear to be deployed with a naming convention suggesting Arabic-speaking targets, and contextual indicators point to oil and gas sector victims in the Middle East. IOCs include 5 C2 domains and 80 file hashes across multiple DanBot variants.

    read more about LYCEUM's Multi-Faceted DanBot Malware Targets Oil and Gas Sector
  10. Public

    Inside Hexane: Sophisticated Cyber Tools and Tactics Targeting Critical Industries

    Hexane (LYCEUM), a threat actor primarily targeting the Middle East’s oil, gas, and telecommunications sectors, has expanded its attack methods. Using spear-phishing emails with malicious Excel macros, the group delivers DanBot, a RAT capable of DNS and HTTP-based command and control, file transfer, and command execution. Additional tools include a PowerShell-based keylogger, credential decryption scripts, and LDAP data-extraction tools targeting Active Directory accounts. They employ social engineering, password spraying, and DNS tunneling to maintain access, frequently rotating C2 infrastructure. The group’s activity indicates continued cyber threats within these critical sectors.

    read more about Inside Hexane: Sophisticated Cyber Tools and Tactics Targeting Critical Industries
  11. Public

    LYCEUM's Cyber Campaign on Middle Eastern Sectors: An In-depth Analysis

    Secureworks CTU's August 2019 report introduces LYCEUM (also known as HEXANE), an emerging Iranian-linked threat group that began targeting oil and gas organizations in the Middle East in May 2019, with earlier activity against South African targets dating to April 2018. The group gains initial access via password spraying or brute-force attacks against corporate email accounts, then uses the compromised accounts to send spearphishing emails with malicious Excel attachments to executives, HR staff, and IT personnel. The Excel files embed a VBA macro dropper called DanDrop that extracts, Base64-decodes, and installs DanBot — a C#/.NET RAT using both DNS (IPv4 A and IPv6 AAAA records) and HTTP channels for C2 communication — via a scheduled task. Post-intrusion tools include kl.ps1 (a PowerShell keylogger storing captured keystrokes as Base64 in scheduled-task deployments), Decrypt-RDCMan.ps1 (a PoshC2 component used to decrypt stored RDP credentials within one hour of initial access), and Get-LAPSP.ps1 (a PowerView-based LDAP account enumeration script). DanBot contains a consistent typo in its HTTP User-Agent — "Accept-Enconding" — which serves as a reliable network detection indicator. LYCEUM registered C2 infrastructure through PublicDomainRegistry.com, Web4Africa, and Hosting Concepts B.V., using security- and web-technology-themed domain names. IOCs include 9 C2 IP addresses, 10 domains, and 3 file hashes for a DanBot variant named AdobeReport.exe. Secureworks noted stylistic similarities to COBALT GYPSY (OilRig/APT34) and COBALT TRINITY (Elfin/APT33) but found insufficient evidence for attribution at time of publication.

    read more about LYCEUM's Cyber Campaign on Middle Eastern Sectors: An In-depth Analysis