Lyceum .NET DNS Backdoor
- First seen
- 2018-06-01 00:00:00
- Malware type
- backdoor, screen-capture
- Family
- Malware family
- Profile updated
- 2026-07-07 14:40:16
Targeted industries: government-and-public-sector energy-and-utilities
Targeted regions: country_code:sa country_code:ae
Context
This .NET written malware is used as backdoor using the dns protocol by a state sponsored threat actor. It implements additional capabilities (e.g. execution of commands, taking screenshots, listing diles/directories/installed applications, and uploading/downloading/execution of files). There are also variants using HTTP (.Net) and also one written in Golang.
Reports & references
- research.checkpoint.com — State Sponsored Attack Groups Capitalise On Russia Ukraine War For Cyber Espionage (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Lyceum Dns Backdoor Dotnet (report)
- zscaler.com — Lyceum Net Dns Backdoor (report)