Lyceum .NET DNS Backdoor

First seen
2018-06-01 00:00:00
Malware type
backdoor, screen-capture
Family
Malware family
Profile updated
2026-07-07 14:40:16

Targeted industries: government-and-public-sector energy-and-utilities

Targeted regions: country_code:sa country_code:ae

Context

This .NET written malware is used as backdoor using the dns protocol by a state sponsored threat actor. It implements additional capabilities (e.g. execution of commands, taking screenshots, listing diles/directories/installed applications, and uploading/downloading/execution of files). There are also variants using HTTP (.Net) and also one written in Golang.

Reports & references

  • research.checkpoint.com — State Sponsored Attack Groups Capitalise On Russia Ukraine War For Cyber Espionage (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Lyceum Dns Backdoor Dotnet (report)
  • zscaler.com — Lyceum Net Dns Backdoor (report)

External references