HEXANE
MITRE ATT&CK: G1001 View on attack.mitre.org
Aliases: Lyceum, Siamesekitten, Spirlin, COBALT LYCEUM, HEXANE, UNC1530, MYSTICDOME, siamesekitten, Chrono Kitten, Storm-0133
- First seen
- 2017-01-01 00:00:00
- Origin
- IR
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Profile updated
- 2026-07-07 11:52:10
Targeted industries: energy-and-utilities technology-and-telecommunications transportation-and-logistics
Targeted regions: country_code:il country_code:sa country_code:kw country_code:ma country_code:tn
Context
HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.
Detection coverage
- 18 YARA rules
- 554 Sigma rules
Malware & tools used
- Credentials from Password Stores (attack-pattern)
- Command Obfuscation (attack-pattern)
- Gather Victim Identity Information (attack-pattern)
- System Information Discovery (attack-pattern)
- Domains (attack-pattern)
- Brute Force (attack-pattern)
- Scheduled Task (attack-pattern)
- Malicious File (attack-pattern)
- Exfiltration to Cloud Storage (attack-pattern)
- Social Media Accounts (attack-pattern)
- Internet Connection Discovery (attack-pattern)
- Windows Management Instrumentation Event Subscription (attack-pattern)
- Local Groups (attack-pattern)
- Remote System Discovery (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Email Accounts (attack-pattern)
- Password Spraying (attack-pattern)
- Bidirectional Communication (attack-pattern)
- Tool (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- PowerShell (attack-pattern)
- Upload Malware (attack-pattern)
- Email Addresses (attack-pattern)
- Email Accounts (attack-pattern)
- System Owner/User Discovery (attack-pattern)
Reports & references
- services.google.com — Tool Of First Resort Israel Hamas War Cyber (report)
- secureworks.com — Lyceum Takes Center Stage In Middle East Campaign (report)
- secureworks.com — Cobalt Lyceum (report)
- prevailion.com — Latest Targets Of Cyber Group Lyceum (report)
- clearskysec.com — Siamesekitten (report)
- vblocalhost.com — Vb2021 Kayal Etal (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- MITRE ATT&CK — G1001 (report)
- dragos.com — Hexane (report)
- accenture.com — Iran Based Lyceum Campaigns (report)
External references
- mitre-attack — G1001
- Spirlin
- Siamesekitten
- Lyceum
- Accenture Lyceum Targets November 2021
- ClearSky Siamesekitten August 2021
- Dragos Hexane
- Kaspersky Lyceum October 2021
- SecureWorks August 2019
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy