Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: Lyceum, Siamesekitten, Spirlin
36
techniques
12
software
11,227
corpus matches
profile
HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.
techniques
36 attributed · most-instrumented first
software
12 malware & tools attributed
Mimikatz
S0002
Ping
S0097
ipconfig
S0100
netstat
S0104
BITSAdmin
S0190
Empire
S0363
PoshC2
S0378
DanBot
S1014
Milan
S1015
Shark
S1019
read this carefully
11,227 corpus matches is not attribution
That count is indicators which exhibit techniques HEXANE is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+24 more techniques
Kevin
S1020
DnsSystem
S1021
showing 30 of 11,227
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.