Also known as: HEXANE, COBALT LYCEUM, UNC1530, Spirlin, MYSTICDOME, siamesekitten, Chrono Kitten, Storm-0133, tracked as, APT 35, Charming Kitten, Cobalt, Diago, OilRig, Earth Simnavaz, Helix Kitten, is a, the Gate of Execution, Tech Sectors, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, Agrius, APT34
Lyceum has been identified in the public domain since at least 2014, but remains active, as evidenced by a June–July 2026 campaign targeting Israeli organizations. The malware chain begins with a macro‑enabled Office document that installs a .NET executable named DnsSystem.exe (referred to generically as Lyceum.NET DNS Backdoor). The backdoor registers a custom attacker‑controlled DNS server – exemplified by "cyberclub.one" – and uses TXT, A, and AAAA records both for command payload delivery and data exfiltration., In parallel, the group leverages Microsoft Graph API to create calendar events dated 2050 with encrypted file attachments. These fabricated events function as a second, low‑profile C&C conduit that bypasses typical network controls by embedding commands in seemingly innocuous Office calendar items. The attacker encrypts inbound and outbound traffic separately using asymmetric RSA keys for authentication and symmetric AES-256-GCM for confidentiality., Lyceum’s toolset showcases advanced persistence via the Windows Startup folder, registry run‑keys (e.g., Security Support Provider), WMI event subscriptions, and scheduled tasks on compromised hosts. It also demonstrates extensive credential gathering – from LSASS memory dumps with Mimikatz to clear‑text Windows credentials in Winlogon logs – coupled with brute‑force/ password‑spraying mechanisms on both local and domain accounts., The actor’s operations reflect a high level of sophistication, employing DNS hijacking, protocol tunneling, obfuscated command payloads mixed with junk data, and legitimate system utilities masquerading. This approach allows Lyceum to remain under the radar while extracting sensitive government, energy, telecom, and industrial control information., While specific details regarding initial access vary across campaigns – ranging from supply‑chain exploits targeting Microsoft Exchange (e.g., Appcmd.exe) to spearphishing attachments – the consistent thread is the establishment of resilient, stealthy backdoors that maintain bidirectional communication over encrypted DNS traffic or Microsoft Graph API channels.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Lyceum, a name used by multiple Iranian APT groups (HEXANE, HOPE), is executing focused espionage against Israeli and broader Middle Eastern government, energy, telecom, defense, and education entities. The group employs a sophisticated .NET DNS backdoor that hijacks DNS traffic and Microsoft Graph API to establish covert command‑and‑control channels, encrypting communications with hybrid RSA/AES-256-GCM and staging exfiltrated data on local hosts before transmission.
Goals & Targeting
Lyceum’s strategic remit appears to revolve around gathering covert intelligence on Middle Eastern critical infrastructure. By focusing on Israel and neighboring states, they likely target high‑value government agencies, energy operators, telecommunications providers, defense contractors and educational institutions. The attacker compiles data ranging from system logs and configuration files to encrypted documents, then exfiltrates it via the same hidden C&C channels that maintain persistence.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
During the most recent campaign (June–July 2026) Lyceum infected at least twelve distinct endpoints across Iranian and Israeli infrastructures, though only three remained active at detection time. The attacks followed a disciplined operational tempo: initial infiltration via macro or Exchange vulnerability, deployment of the .NET backdoor, staging of data in hidden directories (often under the "AppData\Roaming" folder), then exfiltration through either DNS TLD queries or Microsoft Graph calendar events dated in the far future. Victims have consistently been governmental ministries, energy companies, and telecom operators with high-value control systems or policy content.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis draws from multiple reputable reports and technical dissections, giving a high degree of confidence that Lyceum is an Iranian-sponsored espionage actor employing .NET‑based DNS backdoors and Microsoft Graph API manipulation. However, some gaps remain regarding the exact initial access vectors in each campaign and the full extent of the toolset across all operations; further fielding data would refine attribution timelines.
No campaigns linked yet.
No observed data linked yet.
36
Techniques
49
Tools
0
Campaigns
40
IOCs
0
Observed Data
11
Tactics