Lyceum .NET TCP Backdoor

First seen
2020-07-01 00:00:00
Malware type
backdoor, screen-capture
Profile updated
2026-07-07 14:40:18

Targeted industries: energy-and-utilities government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:sa country_code:qa

Context

This .Net written malware is used as backdoor using the http protocol by a state sponsored threat actor. It implements additional capabilities (e.g. execution of commands, taking screenshots, listing diles/directories/installed applications, and uploading/downloading/execution of files). There are also variants using DNS (.Net) and also one written in Golang.

Reports & references

  • research.checkpoint.com — State Sponsored Attack Groups Capitalise On Russia Ukraine War For Cyber Espionage (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Lyceum Http Backdoor Dotnet (report)

External references