◇ SIGN IN
← all actors
apt

HEXANE (Lyceum)

activemedium confidence
APT / State-sponsored
LyceumSiamesekittenSpirlinCavern Manticore
Attribution
Iran — assessed state-aligned (MOIS-linked in recent reporting)
Origin
Iran
First seen
2017
Last active
2025
Motivation
Espionage
Confidence
medium
MENA targeting
Israel, Saudi Arabia, Kuwait, Morocco, Tunisia
Sectors
Oil & gas, telecom, aviation, ISPs
MITRE ATT&CK
Why it mattersState-sponsored / APT actor, medium confidence, documented targeting Israel, Saudi Arabia, Kuwait (Oil & gas, telecom, aviation sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

HEXANE (Lyceum) is an Iranian cyber-espionage group active since at least 2017 that targets oil-and-gas, telecom, aviation, and ISP organizations across the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia.

History

HEXANE was first identified by Dragos around 2018–2019 and has been tracked by multiple vendors under overlapping names including Lyceum, Siamesekitten, and Spirlin. Its TTPs resemble those of APT33 and OilRig, but differences in victimology and tooling have led analysts to track it as a separate Iranian entity; recent reporting increasingly links it to MOIS and to the OilRig orbit.

Operationally the group has favored credential theft, password spraying, DNS-tunneling and custom backdoors (the 'DanBot'/Milan/Shark tool lineage), and social-engineering lures such as fake job offers and HR themes. It has repeatedly upgraded its malware to improve stealth in politically motivated espionage against strategic-infrastructure operators.

MENA and North Africa are the group's focus. Campaigns have hit ISPs and telecom operators in Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia; earlier Israeli targeting included IT and technology firms lured with job-offer pretexts. Telecom and ISP compromise supports downstream surveillance and access to subscriber communications.

HEXANE remains active in 2024–2025. Researchers have documented operational overlaps with MuddyWater — with MuddyWater likely acting as an initial-access broker in January–February 2025 activity against Israeli manufacturing — and reporting on a modular C2 framework dubbed 'Cavern Manticore' assessed as MOIS-linked and tied to the Lyceum subgroup targeting Israeli government and IT-provider entities.

Notable campaigns

2019
DanBot / energy-sector espionage
Dragos-documented targeting of oil-and-gas and critical-infrastructure operators in the Middle East.
2021
Siamesekitten / job-lure campaign
Impersonation and fake-job lures against Israeli firms (ChipPc, Software AG) to deploy backdoors.
2021
Telecom & ISP upgrade campaign
Upgraded malware against telecoms and ISPs in Israel, Saudi Arabia, Morocco, and Tunisia.
2025
Cavern Manticore / MuddyWater overlap
Modular C2 framework against Israeli government and IT providers, with MuddyWater acting as initial-access broker.