HEXANE

G1001

Threat group.View on attack.mitre.org

About this group

HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.

Techniques used36

Procedure examples36

TechniqueProcedure example
T1010
Application Window Discovery

HEXANE has used a PowerShell-based keylogging tool to capture the window title.

T1016
System Network Configuration Discovery

HEXANE has used Ping and `tracert` for network discovery.

T1016.001
Internet Connection Discovery

HEXANE has used tools including BITSAdmin to test internet connectivity from compromised hosts.

T1018
Remote System Discovery

HEXANE has used `net view` to enumerate domain machines.

T1021.001
Remote Desktop Protocol

HEXANE has used remote desktop sessions for lateral movement.

T1027.010
Command Obfuscation

HEXANE has used Base64-encoded scripts.

T1033
System Owner/User Discovery

HEXANE has run `whoami` on compromised machines to identify the current user.

T1049
System Network Connections Discovery

HEXANE has used netstat to monitor connections to specific ports.

T1053.005
Scheduled Task

HEXANE has used a scheduled task to establish persistence for a keylogger.

T1056.001
Keylogging

HEXANE has used a PowerShell-based keylogger named `kl.ps1`.

T1057
Process Discovery

HEXANE has enumerated processes on targeted systems.

T1059.001
PowerShell

HEXANE has used PowerShell-based tools and scripts for discovery and collection on compromised hosts.

T1059.005
Visual Basic

HEXANE has used a VisualBasic script named `MicrosoftUpdator.vbs` for execution of a PowerShell keylogger.

T1069.001
Local Groups

HEXANE has run `net localgroup` to enumerate local groups.

T1082
System Information Discovery

HEXANE has collected the hostname of a compromised machine.

View all 36 procedure examples

Software12

Campaigns0

None recorded.

References4

  1. Accenture Lyceum Targets November 2021 Open source
    Accenture. (2021, November 9). Who are latest targets of cyber group Lyceum?. Retrieved June 16, 2022.
  2. ClearSky Siamesekitten August 2021 Open source
    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.
  3. Dragos Hexane Open source
    Dragos. (n.d.). Hexane. Retrieved October 27, 2019.
  4. Kaspersky Lyceum October 2021 Open source
    Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.