logo

LYCEUM__2019__Cyber_Threat_Group_LYCEUM_Takes_Center_Stage_in_Middle_East_Campaign.pdf

ID: f637620b-a73d-4679-a068-332affbe3388

STIX ID: report--f637620b-a73d-4679-a068-332affbe3388

Threat Score

75/100

Uploaded: 2026-08-15

Published Date: 2019-08-29

Last Modified Date: 2019-08-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Secureworks CTU describes LYCEUM (also reported as HEXANE), an emerging APT that has conducted multi-year spearphishing and credential-based intrusions against energy and critical infrastructure targets in the Middle East, deploying DanBot (a C# RAT) via malicious Excel macros (DanDrop), a PowerShell keylogger (kl.ps1), and post-exploitation scripts; the report includes technical behavior, C2 details (DNS/HTTP), domains/IPs, file hashes, and mitigation recommendations such as MFA, enhanced endpoint visibility, and phishing awareness.