Also known as: Lyceum, Siamesekitten, Spirlin, HEXANE, COBALT LYCEUM, UNC1530, MYSTICDOME, Chrono Kitten, Storm-0133
HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.(Citation: Dragos Hexane)(Citation: Kaspersky Lyceum October 2021)(Citation: ClearSky Siamesekitten August 2021)(Citation: Accenture Lyceum Targets November 2021)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
HEXANE, an unspecified cyber threat actor also known as Lyceum, Siamesekitten, and others, primarily engages in espionage activities targeting critical sectors such as government, energy, telecommunications, education, and defense across the Middle East and Africa. The group has been active since at least 2017, employing sophisticated tactics including keylogging, credential theft, and data exfiltration through various tools and techniques.
Goals & Targeting
HEXANE's primary motivation appears to be espionage, with strategic objectives likely aimed at gathering intelligence from critical infrastructure sectors, government entities, and defense organizations in the Middle East and Africa. The group targets specific industries to acquire sensitive data that could provide a competitive or strategic advantage to its backers, possibly nation-state sponsors given the sophistication of operations and prolonged targeting of critical sectors.
Enhanced Description
HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations primarily in the Middle East and Africa, including countries such as Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. The group's activities have been noted since at least 2017, with campaigns observed by multiple security firms including Dragos, Kaspersky, ClearSky, and Accenture. HEXANE's TTPs are similar to other advanced persistent threat (APT) groups such as APT33 and OilRig but due to differences in victimology and tools used, it is tracked as a distinct entity. The group primarily focuses on espionage objectives, aiming to gather sensitive information from targeted sectors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
HEXANE has conducted multiple campaigns targeting Middle Eastern countries, including Israel, Saudi Arabia, and others. The group's operations demonstrate a focus on critical infrastructure sectors and government entities, with campaigns noted by Dragos, Kaspersky, ClearSky, and Accenture. Notable past operations include attacks against oil & gas companies and telecommunications providers.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the data is high given multiple reputable sources have identified HEXANE and its activities. However, specific details about the group's origins and exact toolset remain unclear, which introduces some uncertainty.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
36
Techniques
5
Tools
0
Campaigns
0
IOCs
0
Observed Data
11
Tactics