Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors lyceum

Also known as: HEXANE, COBALT LYCEUM, UNC1530, Spirlin, MYSTICDOME, siamesekitten, Chrono Kitten, Storm-0133, tracked as, APT 35, Charming Kitten, Cobalt, Diago, OilRig, Earth Simnavaz, Helix Kitten, is a, the Gate of Execution, Tech Sectors, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, Agrius, APT34

Description

Lyceum has been identified in the public domain since at least 2014, but remains active, as evidenced by a June–July 2026 campaign targeting Israeli organizations. The malware chain begins with a macro‑enabled Office document that installs a .NET executable named DnsSystem.exe (referred to generically as Lyceum.NET DNS Backdoor). The backdoor registers a custom attacker‑controlled DNS server – exemplified by "cyberclub.one" – and uses TXT, A, and AAAA records both for command payload delivery and data exfiltration., In parallel, the group leverages Microsoft Graph API to create calendar events dated 2050 with encrypted file attachments. These fabricated events function as a second, low‑profile C&C conduit that bypasses typical network controls by embedding commands in seemingly innocuous Office calendar items. The attacker encrypts inbound and outbound traffic separately using asymmetric RSA keys for authentication and symmetric AES-256-GCM for confidentiality., Lyceum’s toolset showcases advanced persistence via the Windows Startup folder, registry run‑keys (e.g., Security Support Provider), WMI event subscriptions, and scheduled tasks on compromised hosts. It also demonstrates extensive credential gathering – from LSASS memory dumps with Mimikatz to clear‑text Windows credentials in Winlogon logs – coupled with brute‑force/ password‑spraying mechanisms on both local and domain accounts., The actor’s operations reflect a high level of sophistication, employing DNS hijacking, protocol tunneling, obfuscated command payloads mixed with junk data, and legitimate system utilities masquerading. This approach allows Lyceum to remain under the radar while extracting sensitive government, energy, telecom, and industrial control information., While specific details regarding initial access vary across campaigns – ranging from supply‑chain exploits targeting Microsoft Exchange (e.g., Appcmd.exe) to spearphishing attachments – the consistent thread is the establishment of resilient, stealthy backdoors that maintain bidirectional communication over encrypted DNS traffic or Microsoft Graph API channels.

Goals & Targeting

Targeted Sectors

Government
Energy
Telecommunications
Education
Defense
Financial services
Oil gas
Aviation
Critical infrastructure
Non profit
Manufacturing
Healthcare
Transportation
Maritime
Hospitality
Gaming

Targeted Countries / Regions

Israel
IR
middle_east
IL
JP
TW
US
SA
RU
UA
PL
IN
AE
KP
MX
BY
CN

AI Analysis

Grounded in web research
· analyzed in 26 chunks · 5 days ago

Executive Summary

Lyceum, a name used by multiple Iranian APT groups (HEXANE, HOPE), is executing focused espionage against Israeli and broader Middle Eastern government, energy, telecom, defense, and education entities. The group employs a sophisticated .NET DNS backdoor that hijacks DNS traffic and Microsoft Graph API to establish covert command‑and‑control channels, encrypting communications with hybrid RSA/AES-256-GCM and staging exfiltrated data on local hosts before transmission.

Goals & Targeting

Lyceum’s strategic remit appears to revolve around gathering covert intelligence on Middle Eastern critical infrastructure. By focusing on Israel and neighboring states, they likely target high‑value government agencies, energy operators, telecommunications providers, defense contractors and educational institutions. The attacker compiles data ranging from system logs and configuration files to encrypted documents, then exfiltrates it via the same hidden C&C channels that maintain persistence.

Enhanced Description

Key Capabilities

  • DNS hijacking and hijacked backdoor control
  • .NET-based malware deployment (Lyceum.NET DNS Backdoor)
  • Command & Control over TXT, A, AAAA records
  • Microsoft Graph API exploitation for covert C&C
  • Encrypted hybrid RSA/AES-256-GCM communications
  • Data staging in local directories prior to exfiltration (T1074)
  • Command obfuscation using junk data and Base64 encoding (T1001.001)
  • Masquerading legitimate utilities via renaming (T1036.003)
  • Credential dumping with Mimikatz and winlogon logs
  • Brute‑force / password‑spraying across local & domain accounts
  • Persistence via Startup folder, Registry Run Keys, WMI events, Scheduled Tasks
  • Privilege escalation via UAC bypass, SID‑History injection, Pass the Hash
  • Lateral movement via RDP, SMB relay, remote shell execution
  • Supply chain attack potential and exploitation of Microsoft Exchange CVE‑2021‑26855

MITRE ATT&CK Tactics

Command and Control
Credential Access
Collection
Execution
Persistence
Defense Evasion
Initial Access
Resource Development
Exfiltration
Discovery
Privilege Escalation

ATT&CK Techniques

T1071.004
T1572
T1110
T1005
T1204.002
T1036.003
T1068
T1562
T1129
T1105
T1059
T1041
T1003.005
T1547.001
T1074
T1001.001
T1518
T1085
T1053.005
T1016
T1027.010
T1560
T1562.006
T1591
T1519
T1554.002

Software / Tooling

Lyceum.NET DNS Backdoor
.NET DNS Backdoor
DnsSystem.exe
dig.net
Milan
DanBot
Siamesekitten
Spirlin

Campaigns & Victims

During the most recent campaign (June–July 2026) Lyceum infected at least twelve distinct endpoints across Iranian and Israeli infrastructures, though only three remained active at detection time. The attacks followed a disciplined operational tempo: initial infiltration via macro or Exchange vulnerability, deployment of the .NET backdoor, staging of data in hidden directories (often under the "AppData\Roaming" folder), then exfiltration through either DNS TLD queries or Microsoft Graph calendar events dated in the far future. Victims have consistently been governmental ministries, energy companies, and telecom operators with high-value control systems or policy content.

IOC Patterns

  • DNS hijacking patterns
  • Backdoor traffic over DNS
  • Suspicious .NET executable signatures
  • Unusual DNS query volumes to external domains
  • Custom TXT record command delivery
  • Base64‑encoded payloads in DNS A records
  • Encrypted calendar attachments via Microsoft Graph API
  • Renamed legitimate system utilities for masquerading
  • Central staging directories before exfiltration
  • Use of IPv6 AAAA records for credential refresh

Recommended Actions

  • Implement DNS anomaly detection and block known malicious domains such as "cyberclub.one".
  • Deploy endpoint protection that prevents execution of unsigned or unknown .NET binaries.
  • Enable application whitelisting, particularly blocking Office documents containing macros unless verified.
  • Monitor for unusual HTTP requests to Microsoft Graph API endpoints with calendar events dated well beyond current date.
  • Enforce multi‑factor authentication and restrict privilege escalation paths (UAC, SID‑History injection).
  • Configure log collection to flag large file staging directories and suspicious PowerShell executions.
  • Block outbound DNS TXT/A queries carrying Base64 payloads or other obfuscated data.
  • Perform threat hunting for hidden processes that use dig.net resolver utilities.
  • Apply rapid patching of Microsoft Exchange servers, especially CVE‑2021‑26855 (Appcmd.exe).
  • Deploy a robust DLP solution that detects sensitive documents exported via OneDrive or similar cloud services.

Suggested Tags

APT
Iranian
.NET malware
DNS hijacking
cyber espionage
critical infrastructure targeting
Microsoft Graph API exploitation
encrypted C2
staging & exfiltration
credential dumping

Confidence Assessment

The analysis draws from multiple reputable reports and technical dissections, giving a high degree of confidence that Lyceum is an Iranian-sponsored espionage actor employing .NET‑based DNS backdoors and Microsoft Graph API manipulation. However, some gaps remain regarding the exact initial access vectors in each campaign and the full extent of the toolset across all operations; further fielding data would refine attribution timelines.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

URL 3 MD5 Hash 2 Domain 13 Filename 1 IPv4 Address 1

References

Intel Summary

36

Techniques

49

Tools

0

Campaigns

40

IOCs

0

Observed Data

11

Tactics

Tags

APT
espionage
Israel
government
energy
defense
Iranian
.NET malware
DNS hijacking
cyber espionage
critical infrastructure targeting
Microsoft Graph API exploitation
encrypted C2
staging & exfiltration
credential dumping

Details

Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
I
Confidence
55%
Added
Jul 22, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.