Lyceum .NET TCP Backdoor
- First seen
- 2020-07-01 00:00:00
- Malware type
- backdoor, screen-capture
- Profile updated
- 2026-07-07 14:40:18
Targeted industries: energy-and-utilities government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:sa country_code:qa
Context
This .Net written malware is used as backdoor using the http protocol by a state sponsored threat actor. It implements additional capabilities (e.g. execution of commands, taking screenshots, listing diles/directories/installed applications, and uploading/downloading/execution of files). There are also variants using DNS (.Net) and also one written in Golang.
Reports & references
- research.checkpoint.com — State Sponsored Attack Groups Capitalise On Russia Ukraine War For Cyber Espionage (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Lyceum Http Backdoor Dotnet (report)