HEXANE (Lyceum) is an Iranian cyber-espionage group active since at least 2017 that targets oil-and-gas, telecom, aviation, and ISP organizations across the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia.
HEXANE was first identified by Dragos around 2018–2019 and has been tracked by multiple vendors under overlapping names including Lyceum, Siamesekitten, and Spirlin. Its TTPs resemble those of APT33 and OilRig, but differences in victimology and tooling have led analysts to track it as a separate Iranian entity; recent reporting increasingly links it to MOIS and to the OilRig orbit.
Operationally the group has favored credential theft, password spraying, DNS-tunneling and custom backdoors (the 'DanBot'/Milan/Shark tool lineage), and social-engineering lures such as fake job offers and HR themes. It has repeatedly upgraded its malware to improve stealth in politically motivated espionage against strategic-infrastructure operators.
MENA and North Africa are the group's focus. Campaigns have hit ISPs and telecom operators in Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia; earlier Israeli targeting included IT and technology firms lured with job-offer pretexts. Telecom and ISP compromise supports downstream surveillance and access to subscriber communications.
HEXANE remains active in 2024–2025. Researchers have documented operational overlaps with MuddyWater — with MuddyWater likely acting as an initial-access broker in January–February 2025 activity against Israeli manufacturing — and reporting on a modular C2 framework dubbed 'Cavern Manticore' assessed as MOIS-linked and tied to the Lyceum subgroup targeting Israeli government and IT-provider entities.
OSINT feed items linking this actor. Latest Intel →