Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors HEXANE

Also known as: Lyceum, Siamesekitten, Spirlin, HEXANE, COBALT LYCEUM, UNC1530, MYSTICDOME, Chrono Kitten, Storm-0133

Description

HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.(Citation: Dragos Hexane)(Citation: Kaspersky Lyceum October 2021)(Citation: ClearSky Siamesekitten August 2021)(Citation: Accenture Lyceum Targets November 2021)

Goals & Targeting

Targeted Sectors

Government
Energy
Telecommunications
Education
Defense

Targeted Countries / Regions

IR
middle_east

AI Analysis

· 1 week ago

Executive Summary

HEXANE, an unspecified cyber threat actor also known as Lyceum, Siamesekitten, and others, primarily engages in espionage activities targeting critical sectors such as government, energy, telecommunications, education, and defense across the Middle East and Africa. The group has been active since at least 2017, employing sophisticated tactics including keylogging, credential theft, and data exfiltration through various tools and techniques.

Goals & Targeting

HEXANE's primary motivation appears to be espionage, with strategic objectives likely aimed at gathering intelligence from critical infrastructure sectors, government entities, and defense organizations in the Middle East and Africa. The group targets specific industries to acquire sensitive data that could provide a competitive or strategic advantage to its backers, possibly nation-state sponsors given the sophistication of operations and prolonged targeting of critical sectors.

Enhanced Description

HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations primarily in the Middle East and Africa, including countries such as Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. The group's activities have been noted since at least 2017, with campaigns observed by multiple security firms including Dragos, Kaspersky, ClearSky, and Accenture. HEXANE's TTPs are similar to other advanced persistent threat (APT) groups such as APT33 and OilRig but due to differences in victimology and tools used, it is tracked as a distinct entity. The group primarily focuses on espionage objectives, aiming to gather sensitive information from targeted sectors.

Key Capabilities

  • espionage
  • cyber-espionage
  • sophisticated APT tactics
  • credential theft
  • data exfiltration

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Defense Evasion
Disruption
Data Exfiltration

ATT&CK Techniques

T1053.005
T1056.001
T1016.001
T1583.002
T1204.002
T1586.002
T1555
T1583.001
T1010
T1069.001
T1585.002
T1110.003
T1049
T1059.001
T1588.002
T1567.002
T1591.004
T1027.010
T1018
T1518
T1021.001
T1033
T1082
T1608.001
T1589
T1016
T1057
T1546.003
T1534
T1110
T1102.002
T1059.005
T1105

Software / Tooling

DnsSystem
Shark
Milan
DanBot
Kevin

Campaigns & Victims

HEXANE has conducted multiple campaigns targeting Middle Eastern countries, including Israel, Saudi Arabia, and others. The group's operations demonstrate a focus on critical infrastructure sectors and government entities, with campaigns noted by Dragos, Kaspersky, ClearSky, and Accenture. Notable past operations include attacks against oil & gas companies and telecommunications providers.

IOC Patterns

  • Scheduled Task
  • Keylogging
  • Internet Connection Discovery
  • DNS Server Queries
  • Malicious Files
  • Email Account Compromise
  • Credentials from Password Stores
  • Web Browser Credentials Stealing

Recommended Actions

  • Implement endpoint detection and response (EDR) solutions to monitor for known HEXANE TTPs.
  • Conduct regular network monitoring for异常 DNS queries and unusual data exfiltration patterns.
  • Enforce multi-factor authentication across critical systems to mitigate potential brute force or password spraying attempts.
  • Patch and update software promptly to address vulnerabilities targeted by APT groups.
  • Educate employees about phishing tactics, especially spear-phishing emails that HEXANE may employ.

Suggested Tags

APT
espionage
cyber_espionage
Middle_East_focus

Confidence Assessment

Confidence in the data is high given multiple reputable sources have identified HEXANE and its activities. However, specific details about the group's origins and exact toolset remain unclear, which introduces some uncertainty.

ATT&CK Techniques

Discovery
10 techniques
Execution
4 techniques
Resource Development
7 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Accenture Lyceum Targets November 2021 — Accenture. (2021, November 9). Who are latest targets of cyber group Lyceum?. Retrieved June 16, 2022.
  2. ClearSky Siamesekitten August 2021 — ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.
  3. Dragos Hexane — Dragos. (n.d.). Hexane. Retrieved October 27, 2019.
  4. Kaspersky Lyceum October 2021 — Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022.
  5. SecureWorks August 2019 — SecureWorks 2019, August 27 LYCEUM Takes Center Stage in Middle East Campaign Retrieved. 2019/11/19

Intel Summary

36

Techniques

5

Tools

0

Campaigns

0

IOCs

0

Observed Data

11

Tactics

Tags

APT
espionage
cyber_espionage
Middle_East_focus

Details

MITRE ID
G1001
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
I
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--f29b7c5e-2439-42ad-a86f-9f8984fafae3
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.