Threats Feed|Lyceum|Last Updated 30/04/2026|AuthorCertfa Radar|Publish Date09/06/2022

Lyceum Group Unveils Stealthy .NET DNS Backdoor in Middle East Campaign

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Malware,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Zscaler ThreatLabz's June 2022 report documents a new Lyceum Group campaign deploying a .NET-based DNS backdoor named DnsSystem — a customized version of the open-source DIG.net tool — against targets in the Middle East. The malware was delivered via a macro-enabled Microsoft Word document disguised as a news report related to Iranian military affairs, with C2 infrastructure at news-spot.live (85.206.175.199). The document dropped and executed the DnsSystem backdoor, which uses DNS Hijacking for command-and-control: it communicates with the attacker by sending queries to a malicious DNS server and parsing TXT and A record responses for commands. Supported functions include remote command execution, file upload to and download from the C2 server, process and application window discovery, network configuration discovery, and security tool detection. Persistence is achieved by dropping the backdoor binary into the Windows Startup folder. C2 traffic is Base64-encoded. IOCs include 1 IP address (85.206.175.199), 2 domains (news-spot.live, cyberclub.one), 5 URLs, and 2 file hashes. IOC overlap with a concurrent Lyceum campaign (Check Point, March 2022) confirms the same actor and infrastructure.

Detected Targets

TypeDescriptionConfidence
RegionMiddle East Countries
Verified

Extracted IOCs

  • cyberclub[.]one
  • news-spot[.]live
  • 13814a190f61b36aff24d6aa1de56fe2
  • 8199f14502e80581000bd5b3bda250ee
  • 85[.]206.175.199
  • hxxp://news-spot[.]live
  • hxxp://news-spot[.]live/reports/1/45/dnssystem.exe
  • hxxp://news-spot[.]live/reports/1/?id=1111&pid=a28
  • hxxp://news-spot[.]live/reports/1/?id=1111&pid=a40
  • hxxp://news-spot[.]live/reports/1/?id=1111&pid=a52
download

Tip: 10 related IOCs (1 IP, 2 domain, 5 URL, 0 email, 2 file hash) to this threat have been found.

Overlaps

TA453Iranian APTs Exploit Media Sector for Credential Harvesting and Malware Delivery

Source: Proofpoint - July 2022

Detection (one case): cyberclub[.]one

LyceumLyceum's Multi-Dropper Cyber Attack Targets Israeli and Saudi Entities

Source: Check Point - March 2022

Detection (four cases): 13814a190f61b36aff24d6aa1de56fe2, 8199f14502e80581000bd5b3bda250ee, cyberclub[.]one, news-spot[.]live

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions About Lyceum's .NET DNS Backdoor Campaign

Lyceum, an Iranian state-sponsored threat group, deployed a new .NET-based DNS backdoor called DnsSystem against targets in the Middle East in June 2022. The malware was delivered inside a macro-enabled Word document masquerading as an Iranian military news report. Once the victim opened the document and enabled macros, DnsSystem was installed and began communicating with the attackers via a covert DNS-based channel. Zscaler ThreatLabz documented the campaign and published their findings on June 9, 2022.

The campaign is attributed to Lyceum, also tracked as HEXANE and Spirlin. The group is assessed to operate on behalf of the Iranian government, with a history of targeting oil and gas organizations, telecommunications providers, and government entities across the Middle East and Africa. IOC overlap between this campaign and other Lyceum operations — including shared C2 infrastructure at cyberclub.one — directly links it to the same group.

The primary goal was persistent espionage access. DnsSystem gave the attackers full remote control — command execution, file transfer, process enumeration, and network discovery — while remaining stealthy by using DNS as its communication channel. The Iranian military affairs lure also suggests the group was targeting individuals with access to defense or intelligence-related information. The active security tool detection built into the backdoor indicates awareness of defensive environments and intent to avoid detection.

The campaign targeted organizations and individuals in the Middle East. The specific countries or victim organizations are not named in the Zscaler report, but Lyceum's broader targeting history — Israel, Saudi Arabia, Morocco, Tunisia, and other Middle Eastern and North African states — provides context. The Iranian military affairs lure suggests the intended recipients may have had professional interest in Iranian defense or security topics, potentially including government analysts, defense contractors, or journalists.

DnsSystem is a .NET backdoor built by customizing DIG.net, a legitimate open-source DNS query tool. By starting from an existing DNS library, the group could rapidly develop a functional backdoor while leveraging pre-built DNS functionality. The malware queries an attacker-controlled DNS server and embeds commands in TXT and A record responses — a technique that hides malicious traffic inside a protocol almost universally allowed through corporate firewalls. Commands are Base64-encoded for obfuscation. Supported operations include remote command execution, file upload to and download from the C2, process listing, open application window enumeration, network configuration discovery, and detection of security software.

The attackers sent a phishing email with a macro-enabled Word document (.docm) disguised as an Iranian military affairs news report. Opening the document and enabling macros triggered a VBA macro that dropped and executed the DnsSystem binary. The backdoor then dropped a copy of itself into the Windows Startup folder for persistence across reboots, scanned for running security tools, and began beaconing to news-spot.live (85.206.175.199) via DNS queries. Commands received in DNS responses were decoded and executed, with results transmitted back through the same covert channel.

DnsSystem represents a step forward in Lyceum's tooling. Where earlier Lyceum backdoors (DanBot, Milan, Shark) used a mix of HTTP/S and DNS tunneling, DnsSystem is purpose-built entirely around DNS communication — leveraging a customized version of an existing open-source DNS tool rather than coding DNS handling from scratch. The addition of active security tool detection also shows a growing awareness of endpoint defenses. This evolution is consistent with the group's pattern of iterating their custom toolset every 12–18 months to maintain effectiveness against improving defenses.

Block news-spot.live and 85.206.175.199 at the firewall and DNS resolver. Monitor for DNS TXT record queries from endpoints — these are rarely used in normal business operations and are a consistent indicator of DNS tunneling C2. Alert on new files appearing in Windows Startup folder paths placed by Office or script processes. Disable macros in Word documents from external sources and consider blocking .docm attachments at the email gateway. Deploy behavioral detection for .NET processes that enumerate running processes and open windows before making outbound DNS connections — consistent with DnsSystem's pre-execution reconnaissance pattern.

About Affiliation
Lyceum
Lyceum is an Iranian state-linked threat cluster active since at least 2018, targeting oil and gas companies, telecommunications providers, and government organizations across the Middle East and Africa. The group uses credential spraying against personal email accounts as an initial access method before pivoting to corporate networks, and deploys custom .NET malware families including DanBot, Shark, and Milan for persistent access. Lyceum is tracked as HEXANE by Secureworks and SiameseKitten by Israeli researchers, all referring to the same cluster focused on regional energy and telecommunications intelligence collection.
View Lyceum's Insights