« All threats

APT groupMITRE G1001

HEXANE

Also known as: chrono kitten, cobalt lyceum, lyceum, mysticdome, siamesekitten, spirlin, storm-0133, unc1530

[HEXANE](https://attack.mitre.org/groups/G1001) is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. [HEXANE](https://attack.mitre.org/groups/G1001)'s TTPs appear similar to [APT33](https://attack.mitre.org/groups/G0064) and [OilRig](https://attack.mitre.org/groups/G0049) but due to differences in victims and tools it is tracked as a separate entity.(Citation: Dragos Hexane)(Citation: Kaspersky Lyceum October 2021)(Citation: ClearSky Siamesekitten August 2021)(Citation: Accenture Lyceum Targets November 2021)

Victims in the last 90 days0

Most affected countries

No data yet.

Most affected sectors

No data yet.

Priority mitigations

MITRE ATT&CK mitigations that cover the most techniques used by this group.

  1. User Account Management (5 techniques covered)
  2. Privileged Account Management (5 techniques covered)
  3. Restrict Web-Based Content (4 techniques covered)
  4. Password Policies (4 techniques covered)
  5. Behavior Prevention on Endpoint (4 techniques covered)
  6. Multi-factor Authentication (3 techniques covered)
  7. Execution Prevention (3 techniques covered)
  8. Disable or Remove Feature or Program (3 techniques covered)

MITRE ATT&CK techniques

Recent victims

No data yet.

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.