Lyceum's Cyber Espionage Campaign Targets Telecoms and ISPs in the Middle East and Africa
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Malware,RAT,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
Prevailion and Accenture's November 2021 joint report documents Lyceum (also known as HEXANE or Spirlin) targeting telecommunications providers and ISPs in Israel, Morocco, Tunisia, and Saudi Arabia, as well as a Ministry of Foreign Affairs in an unnamed African country. The campaign ran from at least July 2021 through November 2021. Lyceum deployed two updated malware families: Shark, a C#/.NET backdoor using HTTPS for C2 communication, and Milan, a Visual C++/.NET backdoor using DNS tunneling. Both support command execution, file upload and download, and system reconnaissance. Persistence is achieved via Windows scheduled tasks. XOR encoding is used to obfuscate C2 traffic. The group registered 26 C2 domains with security and Windows-update-themed naming patterns (e.g. defenderlive.com, dnsstatus.org, wsuslink.com, windowsupdatecdn.com). Two file hashes for Shark samples are documented. IOC overlap with earlier Lyceum campaigns confirms continuity of tooling and infrastructure across the group's operations from 2019 to 2021.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Government Agencies and Services | Verified |
| Sector | Information Technology | Verified |
| Sector | Telecommunication | Verified |
| Region | Israel | Verified |
| Region | Morocco | Verified |
| Region | Saudi Arabia | Verified |
| Region | Tunisia | Verified |
Extracted IOCs
- akastatus[.]com
- centosupdatecdn[.]com
- checkinternet[.]org
- cybersecnet.co[.]za
- cybersecnet[.]org
- defenderlive[.]com
- defenderstatus[.]com
- digitalmarketingagency[.]net
- dnsanalizer[.]com
- dnscatalog[.]net
- dnscdn[.]org
- dnsstatus[.]org
- excsrvcdn[.]com
- hpesystem[.]com
- indianmombais[.]com
- livednscdn[.]com
- micrsoftonline[.]net
- online-analytic[.]com
- securednsservice[.]net
- sysadminnews[.]info
- uctpostgraduate[.]com
- updatecdn[.]net
- web-traffic[.]info
- windowsupdatecdn[.]com
- wsuslink[.]com
- zonestatistic[.]com
- 17ab5ee10033da8a519c0547581f40677b973345d8c3172a4fde612692188460
- 2f2ef9e3f6db2146bd277d3c4e94c002ecaf7deaabafe6195fddabc81a8ee76c
Tip: 28 related IOCs (0 IP, 26 domain, 0 URL, 0 email, 2 file hash) to this threat have been found.
Overlaps
Source: Virus Bulletin - October 2021
Detection (15 cases): akastatus[.]com, centosupdatecdn[.]com, cybersecnet.co[.]za, defenderlive[.]com, dnscatalog[.]net, dnscdn[.]org, dnsstatus[.]org, hpesystem[.]com, securednsservice[.]net, sysadminnews[.]info, uctpostgraduate[.]com, updatecdn[.]net, web-traffic[.]info, windowsupdatecdn[.]com, wsuslink[.]com
Source: ClearSky - August 2021
Detection (six cases): akastatus[.]com, defenderlive[.]com, defenderstatus[.]com, dnsstatus[.]org, wsuslink[.]com, zonestatistic[.]com
Source: CyberX - January 2020
Detection (five cases): cybersecnet.co[.]za, cybersecnet[.]org, excsrvcdn[.]com, online-analytic[.]com, web-traffic[.]info
Source: Secureworks - August 2019
Detection (five cases): cybersecnet.co[.]za, cybersecnet[.]org, excsrvcdn[.]com, online-analytic[.]com, web-traffic[.]info
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions About Lyceum's Telecom and ISP Campaign
Lyceum, an Iranian-linked threat group also known as HEXANE and Spirlin, targeted telecommunications providers and internet service providers (ISPs) in Israel, Morocco, Tunisia, and Saudi Arabia between July and November 2021. A Ministry of Foreign Affairs in an unnamed African country was also compromised. The group deployed two custom backdoors — Shark and Milan — to maintain persistent access and collect intelligence from these strategic communications networks. Prevailion and Accenture jointly documented the campaign in November 2021.
The campaign is attributed to Lyceum, an Iranian state-sponsored threat group. The group is also tracked as HEXANE by Dragos and Spirlin by other researchers. ESET's subsequent analysis linked Lyceum and SiameseKitten to OilRig (APT34) as a subgroup. Lyceum has been active since at least 2018, with earlier campaigns documented by Secureworks targeting oil and gas organizations in the Middle East and South Africa.
The primary goal was intelligence collection from telecommunications infrastructure. Telecom providers and ISPs have access to vast amounts of communications data — call records, subscriber information, internet traffic metadata, and routing infrastructure — all of which are highly valuable to a state-sponsored actor seeking to monitor individuals or conduct signals intelligence. The Ministry of Foreign Affairs compromise also suggests a diplomatic intelligence collection mission running in parallel.
The campaign hit four countries — Israel, Morocco, Tunisia, and Saudi Arabia — plus an unnamed African country where a Ministry of Foreign Affairs was compromised. The focus on Israel fits Lyceum's broader pattern of targeting Iranian rivals. Morocco, Tunisia, and Saudi Arabia are also strategically important to Iranian intelligence given their regional geopolitical roles and connections. The unnamed African MFA compromise suggests Lyceum's reach extends beyond the Middle East into Africa.
The campaign focused specifically on telecommunications providers and internet service providers — organizations that control the backbone of national communications infrastructure. A government ministry (Foreign Affairs) was also targeted, consistent with diplomatic intelligence collection. Telecom and ISP staff with access to network management systems, subscriber databases, and routing configurations were likely the primary targets within victim organizations.
Lyceum used two backdoors with different C2 channels. Shark communicated over HTTPS, blending traffic with normal web activity. Milan used DNS tunneling, hiding commands inside DNS queries — a method that often evades network monitoring focused on HTTP/S traffic. Both backdoors supported command execution, file upload and download, and system reconnaissance. Persistence was maintained via Windows scheduled tasks, and C2 traffic was XOR-encoded to hinder detection. The group registered 26 C2 domains with security and Windows-update-themed names to appear legitimate.
Telecom providers and ISPs are among the most sensitive targets for state-sponsored espionage — they sit at the center of national communications and can provide access to call records, subscriber data, internet traffic, and routing tables. For Iran, access to telecom infrastructure in Israel, Saudi Arabia, and North Africa provides intelligence on adversaries' communications without needing to compromise individual targets. A Ministry of Foreign Affairs similarly holds diplomatic correspondence, classified cables, and details of foreign policy negotiations.
Block and monitor DNS traffic for the 26 documented C2 domains at network perimeter and DNS resolver level. Alert on outbound DNS queries with unusually long subdomains or abnormally high query rates — a signature of Milan's DNS tunneling C2. Monitor scheduled task creation by non-standard parent processes, especially those referencing .NET executables in user directories. Deploy network detection for XOR-encoded HTTP/S sessions from endpoints. Telecom organizations should audit access to network management systems, routing infrastructure, and subscriber databases, and apply strict least-privilege controls for staff with access to these systems.