HEXANE
Also known as: Lyceum · Siamesekitten · Spirlin
Overview
HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.
Naming & attribution
HEXANE is tracked under 4 names across the industry. It uses 36 documented ATT&CK techniques — more than 72% of the 174 groups tracked here. Activity attributed since at least 2017.
| Name | First reported by |
|---|---|
| Siamesekitten | ClearSky Cyber Security |
| Spirlin | Accenture |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1010Application Window Discovery — used by 3 of 174 groups -
T1583.002DNS Server — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Magic Hound Iran — 23 shared techniques (25% overlap)
- OilRig Iran — 20 shared techniques (22% overlap)
- MuddyWater Iran — 19 shared techniques (22% overlap)
- Sandworm Team Russia — 19 shared techniques (20% overlap)
- FIN8 — 12 shared techniques (20% overlap)
- Moonstone Sleet North Korea — 11 shared techniques (20% overlap)
Malware families with current indicators
One family attributed to HEXANE, carrying 56 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- PoshC2 56 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Targets
Defense · Education · Energy · Government · High-Tech · Military · Telecommunications
Regions
Israel · Middle East
Capabilities
- Custom malware/implant development — ATT&CK: 5 attributed custom malware families
TTPs — 36 techniques across 11 tactics
Reconnaissance
-
T1589Gather Victim Identity Information -
T1589.002Email Addresses -
T1591.004Identify Roles
Resource Development
-
T1583.001Domains -
T1583.002DNS Server -
T1585.001Social Media Accounts -
T1585.002Email Accounts -
T1586.002Email Accounts -
T1588.002Tool -
T1608.001Upload Malware
Execution
-
T1053.005Scheduled Task -
T1059.001PowerShell -
T1059.005Visual Basic -
T1204.002Malicious File
Privilege Escalation
Stealth
-
T1027.010Command Obfuscation
Credential Access
-
T1110Brute Force -
T1110.003Password Spraying -
T1555Credentials from Password Stores -
T1555.003Credentials from Web Browsers
Discovery
-
T1010Application Window Discovery -
T1016System Network Configuration Discovery -
T1016.001Internet Connection Discovery -
T1018Remote System Discovery -
T1033System Owner/User Discovery -
T1049System Network Connections Discovery -
T1057Process Discovery -
T1069.001Local Groups -
T1082System Information Discovery -
T1518Software Discovery
Lateral Movement
-
T1021.001Remote Desktop Protocol -
T1534Internal Spearphishing
Collection
-
T1056.001Keylogging
Command and Control
-
T1102.002Bidirectional Communication -
T1105Ingress Tool Transfer
Exfiltration
-
T1567.002Exfiltration to Cloud Storage
Tools & malware (12)
Milan · Ping · netstat · BITSAdmin · Shark · DnsSystem · DanBot · Empire · ipconfig · Mimikatz · Kevin · PoshC2
Reporting (3)
- Who are latest targets of cyber group Lyceum? — Accenture
- LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST — Kayal, A. et al
- New Iranian Espionage Campaign By “Siamesekitten” - Lyceum — ClearSky Cyber Security