HEXANE — APT Profile
HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
Lyceum, Siamesekitten, Spirlin, Storm-0133, COBALT LYCEUM, UNC1530, MYSTICDOME, Chrono Kitten
IntelFusions coverage (3)
- New spy malware hides its commands inside Microsoft 365 calendars 2026-07-20 · Nation-State
- Iran-linked group targets Israeli firms with a stealthy new spy toolkit 2026-07-06 · Nation-State
- OilRig Outer Space and Juicy Mix Campaigns: Solar and Mango C#/.NET Backdoors Target Israeli Organizations with XOR Encryption, Compromised Israeli Websites as C2 2026-02-16 · Nation-State
Tools & malware
- BITSAdmin LOLBin
- DanBot Remote Access Trojan
- DnsSystem Backdoor
- Empire Post-Exploitation Framework
- ipconfig Network Reconnaissance
- Kevin Backdoor
- Milan Backdoor
- Mimikatz Credential Harvesting
- netstat Network Reconnaissance
- Ping Network Reconnaissance
- PoshC2 Post-Exploitation Framework
- Shark Backdoor
Vendor research
- SecureWorks August 2019 SecureWorks August 2019
- Hexane Dragos
- Dragos. (n.d.). Hexane Dragos
- Who are latest targets of cyber group Lyceum? Accenture
- SecureWorks 2019, August 27 LYCEUM Takes Center Stage in Middle East Campaign Retrieved. 2019/11/19 Secureworks
- LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST Kaspersky
- New Iranian Espionage Campaign By “Siamesekitten” - Lyceum ClearSky
Countries linked to this actor
- Saudi Arabia targets