Lyceum, also known as Hexane, SiameseKitten, Spirlin, and Storm-0133, is an Iranian state-linked cyber-espionage threat actor assessed to operate in support of Iran’s Ministry of Intelligence and Security and commonly described as a subgroup or affiliate within the broader OilRig ecosystem. The group has been associated with intelligence collection operations focused particularly on Israeli organizations, including government, local government, healthcare, and other strategically relevant sectors. Lyceum is known for targeted intrusion activity that combines social engineering, credential theft, host reconnaissance, and abuse of legitimate services and tools. Observed tradecraft includes delivery of malware through malicious email attachments and actor-controlled or impersonation websites that rely on victim execution, staging payloads on fraudulent sites masquerading as trusted organizations, and use of cloud services such as OneDrive for command-and-control or operational support. Post-compromise behavior includes PowerShell-based execution and discovery, collection of host and user information, process enumeration, network discovery using utilities such as ping and tracert, and harvesting of stored credentials. The group has also used scheduled tasks for persistence and has leveraged or customized publicly available tools including Mimikatz, Empire, remote access software, and other dual-use utilities. Reporting has also noted technical and operational overlaps between Lyceum and other Iranian intelligence-linked actors, especially MuddyWater, reflecting coordination or shared resourcing within the Iranian cyber apparatus. Lyceum’s activity is consistent with long-term espionage objectives rather than disruptive or financially motivated operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
65 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an Iranian threat group with operational overlap or coordination with MuddyWater.
Referenced as an Iran-linked threat actor with technical overlaps to Cavern Manticore; described here as a subgroup of OilRig.
Mentioned as a possible tied subgroup connected to Cavern Manticore and associated with Iran-linked activity.
Referenced as an Iranian threat group whose techniques and links overlap with Cavern Manticore, supporting attribution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.