LYCEUM's Multi-Faceted DanBot Malware Targets Oil and Gas Sector
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Malware,RAT,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
CyberX Labs' January 2020 deep-dive analyzes DanBot, the primary Remote Access Trojan used by LYCEUM (HEXANE) against oil and gas sector targets in the Middle East. The report documents DanBot's multi-channel C2 architecture: it uses both DNS tunneling — built on a repurposed and renamed version of the Heijden.Dns open-source library — and HTTP/S communication. DanBot is delivered via spearphishing emails containing malicious XLS files with embedded VBA macros (DanDrop). The malware stores its configuration in encrypted files on disk and achieves persistence via Windows scheduled tasks. It supports both file download and file upload, and uses IPv4 and IPv6 addressing for C2 connectivity. C2 traffic is encoded using Base64 and symmetric encryption. The group also uses proxy infrastructure to mask attacker origins. DanBot variants appear to be deployed with a naming convention suggesting Arabic-speaking targets, and contextual indicators point to oil and gas sector victims in the Middle East. IOCs include 5 C2 domains and 80 file hashes across multiple DanBot variants.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Utilities | Verified |
| Region | Middle East Countries | Medium |
Extracted IOCs
- cybersecnet.co[.]za
- cybersecnet[.]org
- excsrvcdn[.]com
- online-analytic[.]com
- web-traffic[.]info
- 0069d7589319ee99eabc346ed742d08243fc96459a5c3d1770aa984fea4e5c78
- 06853f7f8f67bd6ee83c46f8c0d8c1c1490218afd9c997ac690634ebf199ad00
- 09a7de7e6a6128e4929c08f5f727555379f122df747630a2af474be022c6d156
- 0b5afb306e413db0e1835d865c4aea8f6bbf9774d0541a7617eb4e68716808df
- 0cf9fd6dd259739e6f3e04a6ae303ba0978480e8374ba28ae7ea623ecec15959
- 0da8032bede8aa92c42fa7d7ea2b9397e5ec5c02faaa7b8f7c01424885978d64
- 10d0d53f5e5f34c424431492fa4ee95eb2fa4fe6327455384cf508c586dd2851
- 112b8593d0300d21050e977aba3385b8a00fdaea051bd151cda33452e56fbb8c
- 11c52732d7fde12f5f4c6431f8be876ffd73acdd725c4b908b257be1b007a290
- 130a167de132dedee9f2e893dfbb9e0de4c74d5614552aecd3297d110bc3a294
- 14760a9f85e9586c64d936ce4fcbc2ddd68b44d014a7d7d16a72fa2df484b566
- 148e49964b8cb783b413d832f6ec53cfe07d54abe97d0fd9bb9244bc18f5c3a1
- 14d1eb81a5775fe17462d0b82c0ac15f3c8bb88d32b38ec94dd767ad804faba0
- 17d8f73474aed5c8f0c9569ecd0c842d756097f18a2ec8b01ff42961fbf6c67b
- 18fbe86687134090eef2fbfec358c256bef64e310d3814f7f91263d4257df60c
- 28d8dd812f6b5f1e6e96ff9824054d2141a715ff65b2d7e15e9407bc376b55ed
- 2d38d46440ea3dfd6c820bd4d06a9e4812d5cef8e930cc05bea8ffce3188cb4c
- 2fdee65c29c233ba02584f16554fed069fb04e3653106261c09465f2dda76230
- 307281b56f6ec375ae0ae835821e60a374d29c7d7be8403cc50ce2116ee4e6f9
- 308673b70f7966b41b6fb84334f571d2e6c61e8658358ec1efbef38387050119
- 30eb4698adb0bb690f3b0f8911cede411f99356e1b56d9d8a882ddde105ad83f
- 33b02de47f18e6602aa0d5b681048d0a402c4afd3ae7fdde049fd8856e2bf4ca
- 3588d6a0837409035b4e2ae28fd27224bd487fc8ddf7ed8bf6898a3ff3df275f
- 36e41f4e7c8d71020eb845329b096d267ac95f31334d5881c20f24f23821f2a4
- 38c844152e74579ed22ae907886aba82b730edffd19be44fa9afde3ecd10d131
- 3d222195ef7c1537e0d7d4303f73fb66467c55e0b03c52d4a29ae1ea1881fb73
- 43ef6f87e2abc6551943557df7f345aeaf50c881772d953317fc7250b211ff9b
- 4a812cd5eaa46f6ea5f6dba8342f9932ca83b4b1eb78a82c76448d48ab61e5c7
- 4c4cc3473e050b83943e58548a71c72603a934b2daba6d57fd75908323d32776
- 4c7002a2949c865c0a47ca02b8bfee37c1b40f6d26b478b9c8a23b2e63e6c982
- 50037205dfd335da7f0592fad1a2635275d7acca9b330654e606bad886222b18
- 5768d9d503d01331182b980b41b8fb02a269825e89d3e33e08e6de6f5ffa2024
- 5c0a3f7abab8c7dd74116e04f41c61b39b8f508339dfc3ea650eeb7d1b0c6055
- 610204e0c8c5605e766636880a526d264dc7992fb6f633d75310b3251c9fe7b4
- 6582ed657dd9cd073cd6a45e8099100abe576fb0426589df1f06228524cda3f6
- 66a0874a909994f98b78278c25ee8ff39a3a0d5aceee176befd579e16ad3ddd6
- 66d68dcd56c9c6b82dfd859e24c877724b3f3e85eaf16365912d642611674884
- 6873d3a8ac87a78ce15ff5c873d45b7a569e0fe9ffa0c49a57c46a8bd7e6cbe4
- 6c3e2bd77c9799d7e94f57e7f487af073d70aaadff742a052987ef7a77d4e4d6
- 6d7dff50cce977317df65a0bbde1bbff6831c1d500c9c15a88a02b3efa1843b4
- 6f3bcde8f6cfab07587de8bfba5b6bf77397adbe1e8c1a099299d51b404cce1d
- 6fccb31da9193e0d9787171b85b0ee28ab7a42bb24a41b3a7636a0263302a100
- 7272eb4ebc63240d7746f459f28b9e81d2637c37aec476840a6aa11cbd3f73f8
- 72f78276ea06649556c3beaa5a53f1b3faa5e4b2fe094f1e84cc959c70139c02
- 79142958db41c421df96f6db5487939bfb996a3166f4f89c6d9a8cddce9fe64b
- 7a0fa20c19751d6e769a238253e20efc567a201a93b5e7d62395c9a82fbf3fbb
- 7d3d1701d84bcc088bdd893cd8b7d137c65a38c8af95f6e4c390d48bf96f535a
- 88ee0327df7b5ec6e3521a8ad5e9d3b8e1320f79cc928af594a3a55d0f95c5b4
- 8bed5bbb85d88e5f4ad45069788bd29c3b488968e0c2d17ee459c649f47af5a9
- 90ec639cc8b68ccdd3d643f0e07f517a4d02ee93ec14c233807887402421e253
- 93047bd6893fc0a7d601da19b8f501736786ea196cce7eaac28dad93757c64bb
- 9bb5923b3907a83050a0430d0b4f138124fe52fba944c6fa9374ae3ea639c636
- a0a6b54166ce8b25a296762cb2cf25688205ec0fddbeb03bc8532390f2e7bba5
- a36b8f5bb616c40adc2b3c60d5d0706f8ce12d5c6f29257bd7d956556cb76eb5
- a3b25928dbfd93ff1333f6d3557e75622d6885441dc8f4ac40feeda8fec01153
- a846c86ecfc36717f72341ef79d5d5f7bddcb4a03732d021f75513514293598f
- a925c692d675783ebc948f67410987d05624070c6b230fcba635d970fdc5e156
- aa7ef56643d294b442d60137f5a8de15cd8472ecabdad09c9fd7cf64446a35c0
- aa9c1564c7efd80ae61a4b53ffe11f4a0b9b1a6d21b7073985fb7aa87d9e553a
- ae7f19235e6705979282e6c324b615be05edd3c413bfca5de8fb89d840a79181
- aec5a94e21d3a2934593921419c476a8f1a36b875d7356e1d0a00be726bc9488
- b767daab16272144f09db405eec72e42f986e7683753a2c1e143cdbe385818e2
- c160bebea1440d13e997d08181a93e6310e57dd450589e9ce068cfd7eb3d458b
- caa88640979b914cb1dc43442d36dc9fe689089f5f938a6199ca051e86d8557b
- cb8b53bb788758786fe40811136967df2130c356c0f3eb4d23e9b67ab42e7439
- ceedc02e6338c7027d82b4a3a4a43ad971a0342a6f8fa27c47a2520d00bc1a1e
- d5256a0b238b4072ff47fc9c6342399718def2a37085e48487c78a3ce976abdd
- d6643c4e9c424754742d587bd235e5418eefabb2df0794c286adf9550c197516
- d6c7872e9a8c921c6027a089d2e96424c3846de08e9522319cad1e190b42291d
- d6d8ea065e55a623ac542a76be2c00d89f7a00ae6254cd8689b07f7aff4dd2c3
- d6f7b6d8203986b702ed70e0d4db2dd0698af4ef8c635dda63c9cffdccc7457b
- db769cdee96acdd379f2e82ad24ea8c664ac1cda44d805838d16f5f2e5c2a129
- dd2d493238a513d288fd077a97aa5cb7e388f8ee09245b11ed2d0c084982df93
- e2e59decef4ad004c4160359fdb15fdad0b7d4cc5b585bd315e17d1959afe7d9
- e42d49a9660071b69f0bec2ecb5dcc0aa36a1d87ff4f3083ffb5fb1150cef34a
- e536282421723fd40b3ee69e03b5dac810052bdabf837de2433a4557d9271989
- e565e7d62f564a8a7c0951e5e07da1867b068c98f3a2f30473337283b8f13ecb
- ec234ab68ccad3ec53ede9ef3145b7b60ab66a98dc66b177259d070f25bd9aaf
- ec95229e0310c9b6c81be9d9cb7f8e98e6df3b43e586848cbbb815f61955bfaa
- f57f2bcac17f2ad861e09c2a46909f5b838cda0d78a54c9c1717cb94ee86ebf0
Tip: 85 related IOCs (0 IP, 5 domain, 0 URL, 0 email, 80 file hash) to this threat have been found.
Overlaps
Source: Prevailion - November 2021
Detection (five cases): cybersecnet.co[.]za, cybersecnet[.]org, excsrvcdn[.]com, online-analytic[.]com, web-traffic[.]info
Source: Virus Bulletin - October 2021
Detection (two cases): cybersecnet.co[.]za, web-traffic[.]info
Source: Secureworks - August 2019
Detection (six cases): 10d0d53f5e5f34c424431492fa4ee95eb2fa4fe6327455384cf508c586dd2851, cybersecnet.co[.]za, cybersecnet[.]org, excsrvcdn[.]com, online-analytic[.]com, web-traffic[.]info
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions About LYCEUM's DanBot Malware and Oil and Gas Campaign
LYCEUM, an Iranian-linked threat group also known as HEXANE, deployed DanBot — a custom C#/.NET Remote Access Trojan — against oil and gas organizations in the Middle East. The malware was delivered via spearphishing emails containing malicious Excel files. Once installed, DanBot gave attackers persistent remote access and communicated with their command-and-control servers over both DNS tunneling and HTTP/S channels. CyberX published its deep technical analysis of DanBot's architecture in January 2020.
The campaign is attributed to LYCEUM, also tracked as HEXANE and Spirlin. The group is assessed to be Iranian state-sponsored based on its targeting patterns — consistently focused on oil and gas organizations and telecommunications providers in countries of strategic interest to Iran, including Middle Eastern and African targets. ESET's later research linked LYCEUM to OilRig (APT34) as a subgroup.
The primary goal was intelligence collection and persistent access within oil and gas sector networks. DanBot's capabilities — remote command execution, file upload and download, and system profiling — are consistent with a sustained espionage mission rather than a disruptive or financially motivated attack. LYCEUM's focus on energy organizations with ties to Middle Eastern petrochemical production aligns with Iran's interest in monitoring rivals' energy sector operations and capabilities.
The campaign targeted oil and gas organizations in the Middle East. While the report does not name specific victim countries or companies, indicators in DanBot samples (including Arabic-language naming conventions) and IOC overlap with other LYCEUM campaigns that targeted Saudi Arabia and other Gulf states suggest a consistent Middle Eastern focus. The 5 documented C2 domains also overlap with domains used in a contemporaneous Secureworks campaign targeting Saudi-region energy targets.
Oil and gas companies hold proprietary data on production volumes, reserves, infrastructure, contracts, and industrial control systems — all of high intelligence value to a state-sponsored actor seeking to monitor or disrupt rivals' energy sectors. Middle Eastern energy organizations are of particular interest to Iran because their output, pricing, and infrastructure decisions directly affect Iran's own energy revenues and regional influence. DanBot's long campaign life (2018–2021+) reflects the sustained nature of LYCEUM's interest in this sector.
LYCEUM delivered spearphishing emails with malicious Excel (.XLS) attachments. Opening the file and enabling macros triggered DanDrop, a VBA macro that extracted the DanBot payload, Base64-decoded it, and installed it via a Windows scheduled task. DanBot then began beaconing to its C2 servers using two independent channels: DNS tunneling — built on a repurposed version of the open-source Heijden.Dns library — and direct HTTP/S requests. Both channels supported command execution and file transfer. C2 traffic was encrypted using symmetric encryption and Base64-encoded. Encrypted configuration files stored on disk held DanBot's operational settings between reboots.
DanBot's dual C2 design — DNS tunneling plus HTTP/S — gives it a meaningful detection evasion advantage. DNS is allowed through most corporate firewalls as a required protocol, and DNS tunneling is harder to detect than direct HTTP/S connections to known malicious IPs. By maintaining two independent channels, DanBot also ensures the group retains access even if one protocol is blocked. The repurposing of the legitimate Heijden.Dns open-source library for tunneling further reduces the chance of signature-based detection, since parts of the code are shared with a benign library.
Block the 5 documented C2 domains at the DNS resolver and perimeter firewall level. Monitor for outbound DNS queries with long subdomain strings or high query rates — key indicators of DanBot's DNS tunneling. Disable VBA macros in Excel files received externally and block .xlsm and .xls attachments at the email gateway unless operationally required. Alert on scheduled task creation by Excel or VBScript processes. Deploy endpoint behavioral detection for C#/.NET processes generating both DNS and HTTP C2 traffic simultaneously, which is consistent with DanBot's dual-channel architecture. Patch and monitor all internet-facing systems regularly, and enforce MFA on email and remote access to reduce the impact of any credential compromise used as an alternative entry point.