HEXANE
Also reported as Spirlin, Lyceum, Siamesekitten, Storm-0133, LYCEUM and 9 other names. Linked to Iran by four sources.
Reports per quarter
Techniques seen in the last two years
- T1041 4 reports reports only
- T1105 4 reports in ATT&CK
- T1059.003 3 reports reports only
- T1070.004 3 reports reports only
- T1140 3 reports reports only
- T1547.001 3 reports reports only
- T1573.001 3 reports reports only
- T1003.001 2 reports reports only
- T1059.001 2 reports in ATT&CK
- T1071.001 2 reports reports only
Show all 89 techniques Show fewer
- T1074.001 2 reports reports only
- T1082 2 reports in ATT&CK
- T1106 2 reports reports only
- T1112 2 reports reports only
- T1132.001 2 reports reports only
- T1190 2 reports reports only
- T1543.003 2 reports reports only
- T1566.002 2 reports reports only
- T1583 2 reports reports only
- T1583.001 2 reports in ATT&CK
- T1587.001 2 reports reports only
- T1608 2 reports reports only
- T1001 1 report reports only
- T1003.002 1 report reports only
- T1008 1 report reports only
- T1020 1 report reports only
- T1021 1 report reports only
- T1021.001 1 report in ATT&CK
- T1027 1 report reports only
- T1027.007 1 report reports only
- T1027.009 1 report reports only
- T1027.013 1 report reports only
- T1030 1 report reports only
- T1033 1 report in ATT&CK
- T1036 1 report reports only
- T1036.004 1 report reports only
- T1036.005 1 report reports only
- T1046 1 report reports only
- T1047 1 report reports only
- T1048.001 1 report reports only
- T1053 1 report reports only
- T1056.002 1 report reports only
- T1059.006 1 report reports only
- T1059.007 1 report reports only
- T1070.006 1 report reports only
- T1070.009 1 report reports only
- T1078 1 report reports only
- T1090 1 report reports only
- T1091 1 report reports only
- T1102.002 1 report in ATT&CK
- T1134 1 report reports only
- T1134.001 1 report reports only
- T1134.002 1 report reports only
- T1195 1 report reports only
- T1202 1 report reports only
- T1204.001 1 report reports only
- T1218.011 1 report reports only
- T1219 1 report reports only
- T1480 1 report reports only
- T1489 1 report reports only
- T1490 1 report reports only
- T1497.003 1 report reports only
- T1518.001 1 report reports only
- T1546 1 report reports only
- T1555.003 1 report in ATT&CK
- T1557 1 report reports only
- T1559 1 report reports only
- T1559.001 1 report reports only
- T1560.001 1 report reports only
- T1560.003 1 report reports only
- T1564.003 1 report reports only
- T1566.001 1 report reports only
- T1566.003 1 report reports only
- T1567 1 report reports only
- T1567.002 1 report in ATT&CK
- T1569.002 1 report reports only
- T1573.002 1 report reports only
- T1583.003 1 report reports only
- T1583.004 1 report reports only
- T1583.006 1 report reports only
- T1585.002 1 report in ATT&CK
- T1585.003 1 report reports only
- T1586.002 1 report in ATT&CK
- T1588.002 1 report in ATT&CK
- T1591 1 report reports only
- T1595.002 1 report reports only
- T1620 1 report reports only
- T1622 1 report reports only
- T1659 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2012-5687
- CVE-2014-4404 KEV
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-1130 KEV
- CVE-2015-1635 KEV
- CVE-2015-2051 KEV
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-11882 KEV ransomware
Show all 63 CVEs Show fewer
- CVE-2017-5638 KEV ransomware
- CVE-2018-10562 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-6055
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-0808 KEV
- CVE-2019-0859 KEV ransomware
- CVE-2019-1132 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11707 KEV
- CVE-2019-11708 KEV
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-1579 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-3568 KEV
- CVE-2019-5786 KEV
- CVE-2019-6225
- CVE-2019-7286 KEV
- CVE-2019-7287 KEV
- CVE-2019-8518
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-25748
- CVE-2021-26084 KEV ransomware
- CVE-2021-26605
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-36934 KEV
- CVE-2021-38647 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2022-26134 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2023-36884 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2024-11182 KEV
- CVE-2024-49039 KEV ransomware
- CVE-2024-9680 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
Show all 47 reports Show fewer
-
OilRig's persistent attacks using cloud service-powered downloaders
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor OilRig's persistent attacks using cloud service-powered downloaders
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Lyceum .NET DNS Backdoor
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
State-sponsored Attack Groups Capitalise on Russia-Ukraine War for Cyber Espionage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor State-sponsored Attack Groups Capitalise on Russia-Ukraine War for Cyber Espionage
-
Iranian Hackers Using New Marlin Backdoor in 'Out to Sea' Espionage Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Hackers Using New Marlin Backdoor in 'Out to Sea' Espionage Campaign
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t32021
-
Who are latest targets of cyber group Lyceum-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who are latest targets of cyber group Lyceum-
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q3 2021
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Pay2Kitten report
-
Ongoing Campaign Leveraging Exchange Vulnerability Potentially Linked to Iran
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ongoing Campaign Leveraging Exchange Vulnerability Potentially Linked to Iran
-
APT_trends_report_Q1_2021_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q1_2021_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q1 2021
-
The ICS Threat Landscape and Activity Groups
The original link failed its last check. Original publisher Detailsfor The ICS Threat Landscape and Activity Groups
-
2020.02.22_APT_threat_report_2019_CN_version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.02.22_APT_threat_report_2019_CN_version
-
Deep Dive into the Lyceum Danbot Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Deep Dive into the Lyceum Danbot Malware
-
North American Electric Cyber Threat Perspective
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor North American Electric Cyber Threat Perspective
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020
-
LYCEUM Takes Center Stage in Middle East Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor LYCEUM Takes Center Stage in Middle East Campaign
-
Cyber Threat Group LYCEUM Takes Center Stage in Middle East Campaign
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Threat Group LYCEUM Takes Center Stage in Middle East Campaign
-
Dragos - Global Oil and Gas Cyber Threat Perspctive
The original link failed its last check. Original publisher Detailsfor Dragos - Global Oil and Gas Cyber Threat Perspctive
Newest first. Details opens the report in Explore.