Threat actor · all actors
HEXANEG1001 state
🇮🇷 IR
aka HEXANE, Lyceum, Siamesekitten, Spirlin, COBALT LYCEUM, UNC1530, MYSTICDOME, Chrono Kitten, Storm-0133
Last updated: 2026-08-20
About this actor
[HEXANE](https://attack.mitre.org/groups/G1001) is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. [HEXANE](https://attack.mitre.org/groups/G1001)'s TTPs appear similar to [APT33](https://attack.mitre.org/groups/G0064) and [OilRig](https://attack.mitre.org/groups/G0049) but due to differences in victims and tools it is tracked as a separate entity.(Citation: Dragos Hexane)(Citation: Kaspersky Lyceum October 2021)(Citation: ClearSky Siamesekitten August 2021)(Citation: Accenture Lyceum Targets November 2021)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
MandiantUNC uncategorised cluster
Secureworkscolour-metal names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 52 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1010Application Window Discovery ↗T1016System Network Configuration Discovery ↗T1016.001Internet Connection Discovery ↗T1018Remote System Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1027Obfuscated Files or Information ↗T1027.010Command Obfuscation ↗T1033System Owner/User Discovery ↗T1049System Network Connections Discovery ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1056Input Capture ↗T1056.001Keylogging ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.005Visual Basic ↗T1069Permission Groups Discovery ↗T1069.001Local Groups ↗T1082System Information Discovery ↗T1102Web Service ↗T1102.002Bidirectional Communication ↗T1105Ingress Tool Transfer ↗T1110Brute Force ↗T1110.003Password Spraying ↗T1204User Execution ↗T1204.002Malicious File ↗T1518Software Discovery ↗T1534Internal Spearphishing ↗T1546Event Triggered Execution ↗T1546.003Windows Management Instrumentation Event Subscription ↗T1555Credentials from Password Stores ↗T1555.003Credentials from Web Browsers ↗T1567Exfiltration Over Web Service ↗T1567.002Exfiltration to Cloud Storage ↗T1583Acquire Infrastructure ↗T1583.001Domains ↗T1583.002DNS Server ↗T1585Establish Accounts ↗T1585.001Social Media Accounts ↗T1585.002Email Accounts ↗T1586Compromise Accounts ↗T1586.002Email Accounts ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1589Gather Victim Identity Information ↗T1589.002Email Addresses ↗T1591Gather Victim Org Information ↗T1591.004Identify Roles ↗T1608Stage Capabilities ↗T1608.001Upload Malware ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 19 / 52 | 37% |
CM-6 | 18 / 52 | 35% |
CM-2 | 17 / 52 | 33% |
AC-3 | 14 / 52 | 27% |
AC-6 | 13 / 52 | 25% |
AC-2 | 12 / 52 | 23% |
CA-7 | 12 / 52 | 23% |
CM-7 | 12 / 52 | 23% |
SI-3 | 12 / 52 | 23% |
AC-5 | 9 / 52 | 17% |
IA-2 | 9 / 52 | 17% |
AC-4 | 8 / 52 | 15% |
SC-7 | 8 / 52 | 15% |
AC-20 | 7 / 52 | 13% |
CM-5 | 7 / 52 | 13% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Magic Hound 0.29
- APT42 0.27
- Sandworm Team 0.27
- FIN8 0.26
- TA2541 0.25
Same nation-state
- HomeLand Justice 1.00
- Outer Space 1.00
- Juicy Mix 1.00
- Cleaver 1.00
- OilRig 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00