LYCEUM__2019__Cyber_Threat_Group_LYCEUM_Takes_Center_Stage_in_Middle_East_Campaign.pdf
ID: f637620b-a73d-4679-a068-332affbe3388
STIX ID: report--f637620b-a73d-4679-a068-332affbe3388
Threat Score
75/100
Uploaded: 2026-08-15
Published Date: 2019-08-29
Last Modified Date: 2019-08-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Secureworks CTU describes LYCEUM (also reported as HEXANE), an emerging APT that has conducted multi-year spearphishing and credential-based intrusions against energy and critical infrastructure targets in the Middle East, deploying DanBot (a C# RAT) via malicious Excel macros (DanDrop), a PowerShell keylogger (kl.ps1), and post-exploitation scripts; the report includes technical behavior, C2 details (DNS/HTTP), domains/IPs, file hashes, and mitigation recommendations such as MFA, enhanced endpoint visibility, and phishing awareness.
