Threats Feed|Lyceum|Last Updated 30/04/2026|AuthorCertfa Radar|Publish Date09/11/2021

Lyceum's Cyber Espionage Campaign Targets Telecoms and ISPs in the Middle East and Africa

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Malware,RAT,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Prevailion and Accenture's November 2021 joint report documents Lyceum (also known as HEXANE or Spirlin) targeting telecommunications providers and ISPs in Israel, Morocco, Tunisia, and Saudi Arabia, as well as a Ministry of Foreign Affairs in an unnamed African country. The campaign ran from at least July 2021 through November 2021. Lyceum deployed two updated malware families: Shark, a C#/.NET backdoor using HTTPS for C2 communication, and Milan, a Visual C++/.NET backdoor using DNS tunneling. Both support command execution, file upload and download, and system reconnaissance. Persistence is achieved via Windows scheduled tasks. XOR encoding is used to obfuscate C2 traffic. The group registered 26 C2 domains with security and Windows-update-themed naming patterns (e.g. defenderlive.com, dnsstatus.org, wsuslink.com, windowsupdatecdn.com). Two file hashes for Shark samples are documented. IOC overlap with earlier Lyceum campaigns confirms continuity of tooling and infrastructure across the group's operations from 2019 to 2021.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Verified
SectorInformation Technology
Verified
SectorTelecommunication
Verified
RegionIsrael
Verified
RegionMorocco
Verified
RegionSaudi Arabia
Verified
RegionTunisia
Verified

Extracted IOCs

  • akastatus[.]com
  • centosupdatecdn[.]com
  • checkinternet[.]org
  • cybersecnet.co[.]za
  • cybersecnet[.]org
  • defenderlive[.]com
  • defenderstatus[.]com
  • digitalmarketingagency[.]net
  • dnsanalizer[.]com
  • dnscatalog[.]net
  • dnscdn[.]org
  • dnsstatus[.]org
  • excsrvcdn[.]com
  • hpesystem[.]com
  • indianmombais[.]com
  • livednscdn[.]com
  • micrsoftonline[.]net
  • online-analytic[.]com
  • securednsservice[.]net
  • sysadminnews[.]info
  • uctpostgraduate[.]com
  • updatecdn[.]net
  • web-traffic[.]info
  • windowsupdatecdn[.]com
  • wsuslink[.]com
  • zonestatistic[.]com
  • 17ab5ee10033da8a519c0547581f40677b973345d8c3172a4fde612692188460
  • 2f2ef9e3f6db2146bd277d3c4e94c002ecaf7deaabafe6195fddabc81a8ee76c
download

Tip: 28 related IOCs (0 IP, 26 domain, 0 URL, 0 email, 2 file hash) to this threat have been found.

Overlaps

LyceumLyceum Intensifies Cyber Espionage on Tunisian Telecom and Aviation Sectors

Source: Virus Bulletin - October 2021

Detection (15 cases): akastatus[.]com, centosupdatecdn[.]com, cybersecnet.co[.]za, defenderlive[.]com, dnscatalog[.]net, dnscdn[.]org, dnsstatus[.]org, hpesystem[.]com, securednsservice[.]net, sysadminnews[.]info, uctpostgraduate[.]com, updatecdn[.]net, web-traffic[.]info, windowsupdatecdn[.]com, wsuslink[.]com

SiameseKittenSiamesekitten APT Targets Israeli IT Firms with Supply Chain Attacks

Source: ClearSky - August 2021

Detection (six cases): akastatus[.]com, defenderlive[.]com, defenderstatus[.]com, dnsstatus[.]org, wsuslink[.]com, zonestatistic[.]com

LyceumLYCEUM's Multi-Faceted DanBot Malware Targets Oil and Gas Sector

Source: CyberX - January 2020

Detection (five cases): cybersecnet.co[.]za, cybersecnet[.]org, excsrvcdn[.]com, online-analytic[.]com, web-traffic[.]info

LyceumLYCEUM's Cyber Campaign on Middle Eastern Sectors: An In-depth Analysis

Source: Secureworks - August 2019

Detection (five cases): cybersecnet.co[.]za, cybersecnet[.]org, excsrvcdn[.]com, online-analytic[.]com, web-traffic[.]info

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions About Lyceum's Telecom and ISP Campaign

Lyceum, an Iranian-linked threat group also known as HEXANE and Spirlin, targeted telecommunications providers and internet service providers (ISPs) in Israel, Morocco, Tunisia, and Saudi Arabia between July and November 2021. A Ministry of Foreign Affairs in an unnamed African country was also compromised. The group deployed two custom backdoors — Shark and Milan — to maintain persistent access and collect intelligence from these strategic communications networks. Prevailion and Accenture jointly documented the campaign in November 2021.

The campaign is attributed to Lyceum, an Iranian state-sponsored threat group. The group is also tracked as HEXANE by Dragos and Spirlin by other researchers. ESET's subsequent analysis linked Lyceum and SiameseKitten to OilRig (APT34) as a subgroup. Lyceum has been active since at least 2018, with earlier campaigns documented by Secureworks targeting oil and gas organizations in the Middle East and South Africa.

The primary goal was intelligence collection from telecommunications infrastructure. Telecom providers and ISPs have access to vast amounts of communications data — call records, subscriber information, internet traffic metadata, and routing infrastructure — all of which are highly valuable to a state-sponsored actor seeking to monitor individuals or conduct signals intelligence. The Ministry of Foreign Affairs compromise also suggests a diplomatic intelligence collection mission running in parallel.

The campaign hit four countries — Israel, Morocco, Tunisia, and Saudi Arabia — plus an unnamed African country where a Ministry of Foreign Affairs was compromised. The focus on Israel fits Lyceum's broader pattern of targeting Iranian rivals. Morocco, Tunisia, and Saudi Arabia are also strategically important to Iranian intelligence given their regional geopolitical roles and connections. The unnamed African MFA compromise suggests Lyceum's reach extends beyond the Middle East into Africa.

The campaign focused specifically on telecommunications providers and internet service providers — organizations that control the backbone of national communications infrastructure. A government ministry (Foreign Affairs) was also targeted, consistent with diplomatic intelligence collection. Telecom and ISP staff with access to network management systems, subscriber databases, and routing configurations were likely the primary targets within victim organizations.

Lyceum used two backdoors with different C2 channels. Shark communicated over HTTPS, blending traffic with normal web activity. Milan used DNS tunneling, hiding commands inside DNS queries — a method that often evades network monitoring focused on HTTP/S traffic. Both backdoors supported command execution, file upload and download, and system reconnaissance. Persistence was maintained via Windows scheduled tasks, and C2 traffic was XOR-encoded to hinder detection. The group registered 26 C2 domains with security and Windows-update-themed names to appear legitimate.

Telecom providers and ISPs are among the most sensitive targets for state-sponsored espionage — they sit at the center of national communications and can provide access to call records, subscriber data, internet traffic, and routing tables. For Iran, access to telecom infrastructure in Israel, Saudi Arabia, and North Africa provides intelligence on adversaries' communications without needing to compromise individual targets. A Ministry of Foreign Affairs similarly holds diplomatic correspondence, classified cables, and details of foreign policy negotiations.

Block and monitor DNS traffic for the 26 documented C2 domains at network perimeter and DNS resolver level. Alert on outbound DNS queries with unusually long subdomains or abnormally high query rates — a signature of Milan's DNS tunneling C2. Monitor scheduled task creation by non-standard parent processes, especially those referencing .NET executables in user directories. Deploy network detection for XOR-encoded HTTP/S sessions from endpoints. Telecom organizations should audit access to network management systems, routing infrastructure, and subscriber databases, and apply strict least-privilege controls for staff with access to these systems.

About Affiliation
Lyceum
Lyceum is an Iranian state-linked threat cluster active since at least 2018, targeting oil and gas companies, telecommunications providers, and government organizations across the Middle East and Africa. The group uses credential spraying against personal email accounts as an initial access method before pivoting to corporate networks, and deploys custom .NET malware families including DanBot, Shark, and Milan for persistent access. Lyceum is tracked as HEXANE by Secureworks and SiameseKitten by Israeli researchers, all referring to the same cluster focused on regional energy and telecommunications intelligence collection.
View Lyceum's Insights