Uptime Hamster: 10d 8h 7mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza LYCEUM

LYCEUM

0 incidentes 0 paises 0 sectores apt IR Ultimo: -
Aliases: COBALT LYCEUM, Chrono Kitten, HEXANE, MYSTICDOME, Spirlin, Storm-0133, UNC1530, siamesekitten, danbot, hexane, lyceum, Siamesekitten, DanBot o DanDrop, Kuwait, Sudáfrica, posiblemente, Irán
Ver en IntelTracker → APTTrail →
LYCEUM, also known by aliases such as Hexane, SiameseKitten, and Spirlin, is an Iranian state-sponsored cyber espionage group that first emerged in 2017. This group is distinguished by its consistent focus on targeting oil and gas, energy, and telecommunications sectors primarily across the Middle East and Africa, including countries like Saudi Arabia, Kuwait, and Tunisia. LYCEUM's primary motivation is intelligence gathering and information theft, rather than financial gain or disruption. The group is known for its ability to adapt its toolset, including developing new malware variants and adopting new social engineering tactics to bypass detection, and it has been observed collaborating with other Iran-aligned threat actors.

Aliases del actor

COBALT LYCEUMChrono KittenHEXANEMYSTICDOMESpirlinStorm-0133UNC1530siamesekittendanbothexanelyceumSiamesekittenDanBot o DanDropKuwaitSudáfricaposiblementeIrán

Actores similares

Fox Kittenapt · 1Charming Kittenactor · 1cutting-kittenactor · 1clever-kittenactor · 1charming-kittenactor · 1rocket-kittenactor · 1flash-kittenactor · 1domestic-kittenactor · 1fox-kittenactor · 1tracer-kittenactor · 1
Motivacion