G1001: HEXANE
HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.CitationDragos HexaneCitationKaspersky Lyceum October 2021CitationClearSky Siamesekitten August 2021CitationAccenture Lyceum Targets November 2021
Security context for executives and security teams
HEXANE matters because ATT&CK tracks it as an espionage group targeting oil and gas, telecommunications, aviation, and internet service provider organizations in the Middle East and Africa since at least 2017. For leaders, the practical issue is not just the group name: the mapped behavior emphasizes credential access, discovery, remote access, PowerShell/post-exploitation frameworks, and Windows backdoors, which can turn a single compromised endpoint into broader intelligence loss and operational exposure in critical sectors.
Executive priority
Prioritize this as a readiness and evidence question: can the organization prove it would see credential dumping, suspicious PowerShell, RDP-based lateral movement, scheduled task persistence, unusual DNS/network activity, and commodity or custom backdoor behavior? For critical infrastructure and service-provider environments, the decision value is validating identity controls, segmentation, SOC telemetry depth, and incident-response playbooks before an espionage intrusion becomes prolonged undetected access.
Technical view
ATT&CK provides no official detection text for HEXANE, so defenders should validate coverage from the related software and techniques. Focus on Windows-heavy behaviors supported by the relationships: Mimikatz, BITSAdmin, PowerShell, scheduled tasks, RDP, discovery utilities such as ping, ipconfig, and netstat, and backdoors including DanBot, Milan, Shark, Kevin, and DnsSystem. SOC content should correlate otherwise-common admin utilities with suspicious parent processes, unusual execution context, command obfuscation, credential-access signals, persistence artifacts, and external network or DNS patterns. Treat Empire and PoshC2 as post-exploitation framework coverage requirements across Windows, Linux, and macOS where those platforms exist in the environment.
Likely telemetry
- Endpoint process creation and command-line telemetry, especially for PowerShell, ping, ipconfig, netstat, BITSAdmin, and scheduled task activity
- Windows security logs and authentication events relevant to RDP use, account logons, privilege use, and lateral movement
- PowerShell script block/module/transcription logging where enabled
- EDR or host telemetry for credential dumping behavior associated with Mimikatz-style activity
- Task Scheduler and BITS job creation/modification records
Detection direction
- Do not rely on single-command alerts for ping, ipconfig, netstat, or process/user discovery; tune for sequences, abnormal hosts, unusual users, rare parent processes, and execution after suspected initial access.
- Validate detection of obfuscated commands and PowerShell execution rather than only known hashes or tool names, because related frameworks can be publicly available or modified.
- Correlate RDP activity with valid-account risk indicators such as unusual source/destination pairs, first-time administrative access, off-hours use, and follow-on discovery or credential access.
- Test visibility into scheduled task and BITSAdmin usage, since both can blend with legitimate Windows administration.
- Ensure DNS and egress monitoring can support investigation of DnsSystem-like backdoor behavior without assuming DNS traffic is benign.
Mitigation priorities
- Harden identity first: enforce strong authentication for remote access, reduce standing administrative privilege, and review accounts permitted to use RDP.
- Reduce lateral movement paths through segmentation, especially between user networks, server environments, and critical service-provider or operationally sensitive systems.
- Enable and retain endpoint, PowerShell, authentication, DNS, and network telemetry needed to investigate the mapped behaviors.
- Constrain and monitor administrative utilities such as PowerShell, BITSAdmin, Task Scheduler, and RDP according to business need.
- Apply credential-protection practices and rapid credential rotation procedures for suspected credential dumping or keylogging incidents.
Additional notes and limits
The strongest decision-useful signal in the supplied ATT&CK data is the combination of targeted critical sectors/geographies and relationships to credential dumping, discovery, RDP, PowerShell, scheduled tasks, BITSAdmin, and multiple Windows backdoors. The group is also associated with aliases Lyceum, Siamesekitten, and Spirlin. Similarity to APT33 and OilRig is noted by ATT&CK, but the supplied description says HEXANE is tracked separately due to differences in victims and tools.
ATT&CK does not provide official detection guidance, group-level platforms, or group-level tactics for this object. Relationship descriptions include platform details for related tools and techniques, but they do not prove activity in any specific local environment. This take should be used to prioritize validation and hunting, not to assert current exploitation, attribution, or confirmed detection coverage.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
HEXANE
HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.CitationDragos HexaneCitationKaspersky Lyceum October 2021CitationClearSky Siamesekitten August 2021CitationAccenture Lyceum Targets November 2021
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
