HEXANE (Lyceum) is an Iranian cyber-espionage group active since at least 2017 that targets oil-and-gas, telecom, aviation, and ISP organizations across the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
HEXANE was first identified by Dragos around 2018–2019 and has been tracked by multiple vendors under overlapping names including Lyceum, Siamesekitten, and Spirlin. Its TTPs resemble those of APT33 and OilRig, but differences in victimology and tooling have led analysts to track it as a separate Iranian entity; recent reporting increasingly links it to MOIS and to the OilRig orbit.
Operationally the group has favored credential theft, password spraying, DNS-tunneling and custom backdoors (the 'DanBot'/Milan/Shark tool lineage), and social-engineering lures such as fake job offers and HR themes. It has repeatedly upgraded its malware to improve stealth in politically motivated espionage against strategic-infrastructure operators.
MENA and North Africa are the group's focus. Campaigns have hit ISPs and telecom operators in Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia; earlier Israeli targeting included IT and technology firms lured with job-offer pretexts. Telecom and ISP compromise supports downstream surveillance and access to subscriber communications.
+36 more relationships — see the relationships browser.
HEXANE remains active in 2024–2025. Researchers have documented operational overlaps with MuddyWater — with MuddyWater likely acting as an initial-access broker in January–February 2025 activity against Israeli manufacturing — and reporting on a modular C2 framework dubbed 'Cavern Manticore' assessed as MOIS-linked and tied to the Lyceum subgroup targeting Israeli government and IT-provider entities. In July 2026, Check Point published a dedicated Cavern Manticore disclosure — a MOIS-linked modular .NET C2 framework overlapping HEXANE/Lyceum tradecraft — now tracked as its own actor.
These entities are frequently mentioned together in source material; co-occurrence is not a verified relationship.
Curated links to related activity — not this actor's alias list. Claimed personas are marked unverified; overlap / subgroup edges describe a related but distinct cluster, never the same actor.