← threatfilter.dev / all groups / HEXANE
HEXANE
Also known as: Lyceum · Siamesekitten · Spirlin
Overview
HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.
Targets
Defense · Education · Energy · Government · High-Tech · Military · Telecommunications
Regions
Israel · Middle East
Capabilities
- Custom malware/implant development — ATT&CK: 5 attributed custom malware families
TTPs — 36 techniques across 11 tactics
Reconnaissance
-
T1589Gather Victim Identity Information -
T1589.002Email Addresses -
T1591.004Identify Roles
Resource Development
-
T1583.001Domains -
T1583.002DNS Server -
T1585.001Social Media Accounts -
T1585.002Email Accounts -
T1586.002Email Accounts -
T1588.002Tool -
T1608.001Upload Malware
Execution
-
T1053.005Scheduled Task -
T1059.001PowerShell -
T1059.005Visual Basic -
T1204.002Malicious File
Privilege Escalation
Stealth
-
T1027.010Command Obfuscation
Credential Access
-
T1110Brute Force -
T1110.003Password Spraying -
T1555Credentials from Password Stores -
T1555.003Credentials from Web Browsers
Discovery
-
T1010Application Window Discovery -
T1016System Network Configuration Discovery -
T1016.001Internet Connection Discovery -
T1018Remote System Discovery -
T1033System Owner/User Discovery -
T1049System Network Connections Discovery -
T1057Process Discovery -
T1069.001Local Groups -
T1082System Information Discovery -
T1518Software Discovery
Lateral Movement
-
T1021.001Remote Desktop Protocol -
T1534Internal Spearphishing
Collection
-
T1056.001Keylogging
Command and Control
-
T1102.002Bidirectional Communication -
T1105Ingress Tool Transfer
Exfiltration
-
T1567.002Exfiltration to Cloud Storage
Tools & malware (12)
Milan · Ping · netstat · BITSAdmin · Shark · DnsSystem · DanBot · Empire · ipconfig · Mimikatz · Kevin · PoshC2
Reporting (3)
- Who are latest targets of cyber group Lyceum? — Accenture
- LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST — Kayal, A. et al
- New Iranian Espionage Campaign By “Siamesekitten” - Lyceum — ClearSky Cyber Security