Threats Feed|Lyceum|Last Updated 30/04/2026|AuthorCertfa Radar|Publish Date31/03/2022

Lyceum's Multi-Dropper Cyber Attack Targets Israeli and Saudi Entities

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Malware,Spear Phishing
  • Attack Complexity: High
  • Threat Risk: High Impact/Low Probability

Threat Overview

Check Point Research's March 2022 report documents a Lyceum APT campaign that exploited the Russia-Ukraine war as a lure to target Israeli energy companies and entities in Saudi Arabia. In mid-March 2022, an Israeli energy organization received a spearphishing email from inews-reporter@protonmail[.]com with the subject "Russian war crimes in Ukraine," containing a link to a malicious document on news-spot[.]live hosting a Guardian article as a decoy. The campaign deployed three categories of executable droppers — a .NET DNS dropper, a .NET TCP dropper, and a Golang dropper — each delivering a different backdoor. The .NET DNS backdoor is a modified version of the DnsDig tool using the Heijden.DNS open-source library for DNS tunneling, supporting file upload/download and command execution. The .NET TCP backdoor communicates over raw TCP sockets with a configurable protocol, supporting command execution, screenshots, file listing, installed applications enumeration, and file upload/download/execution. The Golang HTTP backdoor operates in three stages (connectivity check, victim registration, command retrieval) using HTTP POST requests to /GO/1.php, /GO/2.php, and /GO/3.php. All droppers display a decoy PDF (Russia-Ukraine war related or Iranian cyber threat report) while silently downloading and executing the payload. Persistence is achieved via Startup folder placement or scheduled tasks. Attribution indicators include use of Heijden.DNS, DNS tunneling C2, infrastructure overlap with known Lyceum servers on the same ASN, and Protonmail registration addresses.

Detected Targets

TypeDescriptionConfidence
SectorUtilities
Verified
RegionIsrael
Verified
RegionSaudi Arabia
Verified

Extracted IOCs

  • cyberclub[.]one
  • news-reporter[.]xyz
  • news-spot[.]live
  • news-spot[.]xyz
  • science-news[.]live
  • 13814a190f61b36aff24d6aa1de56fe2
  • 1a5489147a888c4f5f32e97ffcb01733
  • 1c444ebeba24dcba8628b7dfe5fec7c6
  • 214011a0d57b1d8238532be4f6414f58
  • 23d174e6a0905fd59b2613d5ac106261
  • 2bc2abefc1a721908bc805894b62227d
  • 37a1514a7a5f9b2c6786096129a30721
  • 37fe608983d4b06a5549247f0e16bc11
  • 53542ec51daf61fba2d26fe91b7d701f
  • 5916e5189ef0050dfcc3cc19382d08d5
  • 6aeca48c9090b301b3fdf9da4382c882
  • 73bddd5f1a0847ae5f5d55e7d9c177f6
  • 8044dc6078b003698d6e1cbbd22a9ea6
  • 8199f14502e80581000bd5b3bda250ee
  • 85ca334f87667bd7fa0c47ae6149353e
  • 8b01dec07856a67db0e0d849bc84fd9e
  • 8d51fbb90ad5942cd1a5a6534bd9d1d7
  • 9fb86915db1b7c00f1a4587de4e052de
  • 9fcad8f97eeae10f7a222eca94cb9a5f
  • a437f997d45bc14e76d0f2482f572a34
  • a5dbfd729b6fd64a6c4fd77a3e356989
  • bcb465cc2257e5777bab431690ca5039
  • c41ffcbd933039bb6981d05b4c4c673e
  • ce186cda677f0120cfdb308803b8e8d8
  • d79687676d2d152aec4143c852bdbc4a
  • d962dd55fde800d972a156f5c63a6243
  • e03c7e3e8957ede592de07d3dca247b7
  • f3b395661cc663c1baad41b439622071
  • f72768f352994ecce3b9e5109fe93eec
  • f8c29040122cf892190bcf3665975d2f
  • f9fd9e32cb04c4fc93e65f48562ecad3
  • 104[.]249.26.60
  • 185[.]243.112.136
  • 85[.]206.175.201
download

Tip: 39 related IOCs (3 IP, 5 domain, 0 URL, 0 email, 31 file hash) to this threat have been found.

Overlaps

TA453Iranian APTs Exploit Media Sector for Credential Harvesting and Malware Delivery

Source: Proofpoint - July 2022

Detection (one case): cyberclub[.]one

LyceumLyceum Group Unveils Stealthy .NET DNS Backdoor in Middle East Campaign

Source: Zscaler - June 2022

Detection (four cases): 13814a190f61b36aff24d6aa1de56fe2, 8199f14502e80581000bd5b3bda250ee, cyberclub[.]one, news-spot[.]live

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions About Lyceum's Multi-Dropper Campaign Against Israeli and Saudi Targets

Lyceum, an Iranian-linked APT group, launched a spearphishing campaign in March 2022 that used the Russia-Ukraine war as a lure to target an Israeli energy company and entities in Saudi Arabia. Victims received emails with links to malicious documents hosted on attacker-controlled infrastructure. The documents displayed legitimate-looking news articles as decoys while silently installing one of three custom backdoors. Check Point Research published the analysis on March 31, 2022, as part of a broader report on APT groups exploiting the conflict.

The campaign is attributed to Lyceum, an Iranian state-sponsored threat group also tracked as HEXANE and Spirlin. Check Point confirmed attribution through multiple indicators: reuse of the Heijden.DNS open-source library consistent with earlier Lyceum campaigns, DNS tunneling C2 architecture, infrastructure overlap with known Lyceum C2 servers on the same ASN, and Protonmail addresses used both to send phishing emails and register the campaign domains — a pattern observed consistently across Lyceum operations.

The goal was cyber espionage — establishing persistent access to energy sector organizations in Israel and Saudi Arabia to collect intelligence of strategic value to Iran. All three backdoors support command execution, file upload and download, and system reconnaissance, consistent with a sustained intelligence collection mission. The use of three different backdoor families with different C2 protocols also suggests the group was testing and diversifying its toolset while maintaining operational resilience.

The campaign primarily targeted an Israeli energy company and entities in Saudi Arabia. Artifacts uploaded to VirusTotal from Saudi Arabia during the same period confirm the regional scope. Decoy documents found on the campaign infrastructure included materials themed around the Russia-Ukraine war, Russian nuclear weapons, and a Ukraine-based job posting — suggesting the lures were crafted for recipients with professional interest in geopolitical and security topics, likely employees at energy and defense-adjacent organizations.

Israeli and Saudi energy organizations hold direct strategic intelligence value for Iran. Israel is Iran's primary regional adversary, and its energy infrastructure and industrial capabilities are of significant interest. Saudi Arabia controls major oil production that competes directly with Iran's economic interests. Lyceum's consistent focus on energy sectors in both countries — dating back to 2018 — reflects a sustained mandate to collect intelligence on these industries. The Russia-Ukraine war lure was effective because energy sector professionals in the Middle East were actively monitoring the conflict's impact on global oil markets.

Lyceum used three parallel attack chains in this campaign. In the first, a spearphishing email linked to a malicious Office document that ran a macro when closed — dropping a payload into the Windows Startup folder for next-reboot execution. In the second and third chains, executable droppers disguised with PDF icons opened a decoy PDF for the victim while silently downloading and installing one of three backdoors: a .NET DNS backdoor (DNS tunneling via modified DnsDig/Heijden.DNS), a .NET TCP backdoor (raw TCP sockets with custom protocol), or a Golang HTTP backdoor (three-stage HTTP POST loop to /GO/1.php, /GO/2.php, /GO/3.php). All three backdoors support command execution, file upload/download, and system reconnaissance. The Golang backdoor also generates a victim ID from an MD5 hash of the username for C2 registration.

The deployment of three separate backdoor families with three different C2 protocols — DNS tunneling, raw TCP sockets, and HTTP POST — is a significant evolution for Lyceum. Earlier campaigns used one or two C2 channels per implant. This multi-dropper approach gives the group flexibility: if one backdoor or C2 channel is detected and blocked, the others remain active. The Golang backdoor is also a new language addition to Lyceum's previously .NET-focused toolkit, reflecting investment in cross-platform capability development. The decoy-on-close macro technique (payload executes when the document is closed rather than opened) is also a evasion refinement not seen in earlier Lyceum campaigns.

Block all five documented C2 domains (news-spot.live, news-spot.xyz, cyberclub.one, science-news.live, news-reporter.xyz) and three IPs (104.249.26.60, 85.206.175.201, 185.243.112.136) at the network perimeter. Monitor for DNS tunneling indicators — high-frequency DNS queries, long subdomains, TXT record queries from endpoints — consistent with the .NET DNS backdoor. Alert on new files dropped into the Windows Startup folder or Public\Downloads directory by Office or script processes. Block macro-enabled Office documents from external sources and specifically monitor for macros that execute on document close. Deploy the three YARA rules published by Check Point (lyceum_dotnet_dns_backdoor, lyceum_dotnet_http_backdoor, lyceum_golang_backdoor) for endpoint and memory scanning.

About Affiliation
Lyceum
Lyceum is an Iranian state-linked threat cluster active since at least 2018, targeting oil and gas companies, telecommunications providers, and government organizations across the Middle East and Africa. The group uses credential spraying against personal email accounts as an initial access method before pivoting to corporate networks, and deploys custom .NET malware families including DanBot, Shark, and Milan for persistent access. Lyceum is tracked as HEXANE by Secureworks and SiameseKitten by Israeli researchers, all referring to the same cluster focused on regional energy and telecommunications intelligence collection.
View Lyceum's Insights