G1001

G1001HEXANE

Description

[HEXANE](https://attack.mitre.org/groups/G1001) is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. [HEXANE](https://attack.mitre.org/groups/G1001)'s TTPs appear similar to [APT33](https://attack.mitre.org/groups/G0064) and [OilRig](https://attack.mitre.org/groups/G0049) but due to differences in victims and tools it is tracked as a separate entity.(Citation: Dragos Hexane)(Citation: Kaspersky Lyceum October 2021)(Citation: ClearSky Siamesekitten August 2021)(Citation: Accenture Lyceum Targets November 2021)

References

  1. https://attack.mitre.org/groups/G1001
  2. https://www.accenture.com/us-en/blogs/cyber-defense/iran-based-lyceum-campaigns
  3. https://www.clearskysec.com/siamesekitten/
  4. https://dragos.com/resource/hexane/
  5. https://vblocalhost.com/uploads/VB2021-Kayal-etal.pdf
  6. https://www.secureworks.com/blog/lyceum-takes-center-stage-in-middle-east-campaign

Software attributed to this4

TypeTargetConfidenceTier
SoftwareDnsSystems1021100%live
SoftwareSharks1019100%live
SoftwareDanBots1014100%live
SoftwareKevins102095%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Group
OilRig
Group
Inception
Group
Moses Staff
Group
Gelsemium
Group
BITTER
Group
APT33
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.