Lyceum, also known as Hexane, SiameseKitten, Spirlin, and Storm-0133, is an Iranian state-linked cyber espionage threat actor widely assessed as operating within or alongside the OilRig activity cluster and associated with Iran’s Ministry of Intelligence and Security (MOIS). The group is known for targeted intelligence collection operations, with reporting frequently linking it to intrusions against government, telecommunications, energy, critical infrastructure, and IT-related organizations in the Middle East, including activity focused on Israeli entities. Lyceum is associated with modular malware development and post-compromise tradecraft centered on stealthy persistence, credential access, reconnaissance, and data theft. Reported tooling and behavior include .NET-based backdoors and plugin-oriented frameworks, use of legitimate enterprise services for covert command-and-control, and techniques intended to blend malicious traffic into normal administrative or cloud activity. Recent reporting has noted low-confidence technical overlaps between Lyceum and the Cavern framework as well as the HollowGraph malware component, including similarities in modular .NET architecture, command structure, and plugin-loading behavior; however, those overlaps are not sufficient for definitive attribution of those operations to Lyceum. The actor’s operational profile is consistent with long-term espionage rather than disruptive or financially motivated activity. Lyceum has been discussed as a subgroup or sub-cluster of OilRig, and its tradecraft has also been compared with other Iranian intrusion sets such as MuddyWater. High-confidence characterization places Lyceum within the broader Iranian intelligence cyber ecosystem, using tailored intrusion chains and modular implants to support strategic collection objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 malware families attributed to this actor across reporting.
15 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
71 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a possible but low-confidence attribution link based on malware similarities to the Cavern framework; no definitive operational attribution is made in the content.
Iran-linked subgroup discussed as a low-confidence attribution candidate for the HollowGraph activity based on technical similarities.
Referenced as an overlapping or related Iran-linked threat actor in connection with Cavern Manticore; no direct attribution by Group-IB.
An Iranian threat group with technical overlaps to the HOLLOWGRAPH activity; the connection is assessed at low confidence.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.