Threats Feed|Lyceum|Last Updated 30/04/2026|AuthorCertfa Radar|Publish Date27/08/2019

LYCEUM's Cyber Campaign on Middle Eastern Sectors: An In-depth Analysis

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Malware,RAT,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Secureworks CTU's August 2019 report introduces LYCEUM (also known as HEXANE), an emerging Iranian-linked threat group that began targeting oil and gas organizations in the Middle East in May 2019, with earlier activity against South African targets dating to April 2018. The group gains initial access via password spraying or brute-force attacks against corporate email accounts, then uses the compromised accounts to send spearphishing emails with malicious Excel attachments to executives, HR staff, and IT personnel. The Excel files embed a VBA macro dropper called DanDrop that extracts, Base64-decodes, and installs DanBot — a C#/.NET RAT using both DNS (IPv4 A and IPv6 AAAA records) and HTTP channels for C2 communication — via a scheduled task. Post-intrusion tools include kl.ps1 (a PowerShell keylogger storing captured keystrokes as Base64 in scheduled-task deployments), Decrypt-RDCMan.ps1 (a PoshC2 component used to decrypt stored RDP credentials within one hour of initial access), and Get-LAPSP.ps1 (a PowerView-based LDAP account enumeration script). DanBot contains a consistent typo in its HTTP User-Agent — "Accept-Enconding" — which serves as a reliable network detection indicator. LYCEUM registered C2 infrastructure through PublicDomainRegistry.com, Web4Africa, and Hosting Concepts B.V., using security- and web-technology-themed domain names. IOCs include 9 C2 IP addresses, 10 domains, and 3 file hashes for a DanBot variant named AdobeReport.exe. Secureworks noted stylistic similarities to COBALT GYPSY (OilRig/APT34) and COBALT TRINITY (Elfin/APT33) but found insufficient evidence for attribution at time of publication.

Detected Targets

TypeDescriptionConfidence
SectorInformation Technology
Verified
SectorTelecommunication
Verified
SectorUtilities
Verified
RegionMiddle East Countries
Verified

Extracted IOCs

  • bsolutions-cloude[.]com
  • cybersecnet.co[.]za
  • cybersecnet[.]org
  • dnscachecloud[.]com
  • dnscloudservice[.]com
  • excsrvcdn[.]com
  • online-analytic[.]com
  • opendnscloud[.]com
  • web-statistics[.]info
  • web-traffic[.]info
  • 9df776b9933fbf95e3d462e04729d074
  • a8f68c928f82edd8a28c0fd25e207929a7dbce23
  • 10d0d53f5e5f34c424431492fa4ee95eb2fa4fe6327455384cf508c586dd2851
  • 104[.]149.37.44
  • 144[.]217.149.61
  • 144[.]217.156.94
  • 158[.]69.187.171
  • 164[.]132.181.82
  • 198[.]50.152.162
  • 62[.]113.196.37
  • 62[.]113.207.181
  • 75[.]87.185.45
download

Tip: 22 related IOCs (9 IP, 10 domain, 0 URL, 0 email, 3 file hash) to this threat have been found.

Overlaps

LyceumLyceum's Cyber Espionage Campaign Targets Telecoms and ISPs in the Middle East and Africa

Source: Prevailion - November 2021

Detection (five cases): cybersecnet.co[.]za, cybersecnet[.]org, excsrvcdn[.]com, online-analytic[.]com, web-traffic[.]info

LyceumLyceum Intensifies Cyber Espionage on Tunisian Telecom and Aviation Sectors

Source: Virus Bulletin - October 2021

Detection (four cases): cybersecnet.co[.]za, dnscloudservice[.]com, opendnscloud[.]com, web-traffic[.]info

LyceumLYCEUM's Multi-Faceted DanBot Malware Targets Oil and Gas Sector

Source: CyberX - January 2020

Detection (six cases): 10d0d53f5e5f34c424431492fa4ee95eb2fa4fe6327455384cf508c586dd2851, cybersecnet.co[.]za, cybersecnet[.]org, excsrvcdn[.]com, online-analytic[.]com, web-traffic[.]info

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions About LYCEUM's Middle East Oil and Gas Campaign

LYCEUM, an Iranian-linked threat group also tracked as HEXANE, launched a campaign against oil and gas organizations in the Middle East starting in May 2019. The group first compromised employee email accounts via password spraying, then used those accounts to send phishing emails with malicious Excel files to executives, HR, and IT staff. The Excel files silently installed a custom remote access trojan called DanBot, which gave attackers persistent access and the ability to move laterally within victim networks. Secureworks CTU published its foundational analysis of LYCEUM in August 2019.

The campaign is attributed to LYCEUM, also known as HEXANE. At the time Secureworks published this report, there was insufficient technical evidence to definitively link LYCEUM to a specific nation-state sponsor, though the group's tradecraft resembled that of known Iranian groups — particularly OilRig/APT34 (COBALT GYPSY) and Elfin/APT33 (COBALT TRINITY). Subsequent reporting and ESET's later analysis linked LYCEUM and Siamesekitten to OilRig as a subgroup.

The primary goal was establishing and expanding access within targeted networks for intelligence collection. LYCEUM focused on obtaining credentials from executives, HR staff, and IT personnel — roles that collectively provide broad network access, sensitive organizational data, and administrative privileges. The group deployed a keylogger, an RDP credential decryptor, and an Active Directory enumeration tool, suggesting a methodical effort to map and escalate access within the target environment rather than a one-time smash-and-grab operation.

The May 2019 campaign targeted oil and gas organizations in the Middle East. Earlier 2018 activity targeted organizations in South Africa using similar tooling. Secureworks warned that future targeting should not be assumed to be limited to the energy sector — telecommunications and other critical infrastructure organizations in the region were also considered at risk based on the group's broader profile.

LYCEUM targeted oil and gas organizations in the Middle East, with a specific focus on employees in executive, HR, and IT roles. These roles were chosen deliberately: executives have access to sensitive business decisions, HR personnel hold account data useful for further phishing operations, and IT staff have access to privileged accounts and network documentation. The group's lures included training schedules and security best practice documents designed to appear legitimate to these specific audiences.

LYCEUM began by spraying common passwords across many employee email accounts to avoid triggering lockout policies. Once an account was compromised, the attackers sent phishing emails from that internal address — significantly increasing the chance of the recipient opening the attachment. The malicious Excel file contained a VBA macro (DanDrop) that silently extracted and installed DanBot via a Windows scheduled task. DanBot then communicated with LYCEUM's C2 servers over both DNS and HTTP, and within about an hour, the attackers deployed additional tools: a PowerShell keylogger (kl.ps1) to capture passwords typed by users, a PoshC2-based tool to decrypt stored RDP credentials (Decrypt-RDCMan.ps1), and an Active Directory enumeration script (Get-LAPSP.ps1) to map user accounts and group memberships across the environment.

Middle Eastern oil and gas organizations hold strategic intelligence value for Iran — their production volumes, contracts, pricing, and infrastructure details are directly relevant to Iran's energy sector competition with Gulf states. The group's consistent focus on HR and IT roles also suggests a supply chain angle: compromising these personnel can yield access credentials and contact lists that enable further attacks on partner organizations. South Africa's energy sector was targeted in 2018, suggesting LYCEUM also has interest in African energy infrastructure connected to the Middle East.

Enforce MFA on all internet-facing services — Office 365, VPNs, and SSO portals — and ensure enrollment is tightly controlled so compromised accounts cannot self-enroll in MFA. Monitor authentication logs for password spraying patterns: multiple failed logins across many accounts from a single IP. Block or alert on outbound DNS traffic to domains matching the DNS-security-theme pattern (dnscachecloud, dnscloudservice, opendnscloud) and on HTTP traffic containing the misspelled header "Accept-Enconding" — a reliable DanBot fingerprint. Alert on scheduled task creation by Excel, VBScript, or PowerShell processes. Deploy endpoint detection for PowerShell accessing Active Directory via LDAP and for keylogger-like API behavior. Maintain regular phishing awareness training focused on internal-sender lures, which are harder for employees to identify as malicious.

About Affiliation
Lyceum
Lyceum is an Iranian state-linked threat cluster active since at least 2018, targeting oil and gas companies, telecommunications providers, and government organizations across the Middle East and Africa. The group uses credential spraying against personal email accounts as an initial access method before pivoting to corporate networks, and deploys custom .NET malware families including DanBot, Shark, and Milan for persistent access. Lyceum is tracked as HEXANE by Secureworks and SiameseKitten by Israeli researchers, all referring to the same cluster focused on regional energy and telecommunications intelligence collection.
View Lyceum's Insights