LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1001: HEXANE

HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.CitationDragos HexaneCitationKaspersky Lyceum October 2021CitationClearSky Siamesekitten August 2021CitationAccenture Lyceum Targets November 2021

EnterpriseG1001GroupObject v2.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

HEXANE matters because ATT&CK tracks it as an espionage group targeting oil and gas, telecommunications, aviation, and internet service provider organizations in the Middle East and Africa since at least 2017. For leaders, the practical issue is not just the group name: the mapped behavior emphasizes credential access, discovery, remote access, PowerShell/post-exploitation frameworks, and Windows backdoors, which can turn a single compromised endpoint into broader intelligence loss and operational exposure in critical sectors.

Executive priority

Prioritize this as a readiness and evidence question: can the organization prove it would see credential dumping, suspicious PowerShell, RDP-based lateral movement, scheduled task persistence, unusual DNS/network activity, and commodity or custom backdoor behavior? For critical infrastructure and service-provider environments, the decision value is validating identity controls, segmentation, SOC telemetry depth, and incident-response playbooks before an espionage intrusion becomes prolonged undetected access.

Technical view

ATT&CK provides no official detection text for HEXANE, so defenders should validate coverage from the related software and techniques. Focus on Windows-heavy behaviors supported by the relationships: Mimikatz, BITSAdmin, PowerShell, scheduled tasks, RDP, discovery utilities such as ping, ipconfig, and netstat, and backdoors including DanBot, Milan, Shark, Kevin, and DnsSystem. SOC content should correlate otherwise-common admin utilities with suspicious parent processes, unusual execution context, command obfuscation, credential-access signals, persistence artifacts, and external network or DNS patterns. Treat Empire and PoshC2 as post-exploitation framework coverage requirements across Windows, Linux, and macOS where those platforms exist in the environment.

Likely telemetry

  • Endpoint process creation and command-line telemetry, especially for PowerShell, ping, ipconfig, netstat, BITSAdmin, and scheduled task activity
  • Windows security logs and authentication events relevant to RDP use, account logons, privilege use, and lateral movement
  • PowerShell script block/module/transcription logging where enabled
  • EDR or host telemetry for credential dumping behavior associated with Mimikatz-style activity
  • Task Scheduler and BITS job creation/modification records

Detection direction

  • Do not rely on single-command alerts for ping, ipconfig, netstat, or process/user discovery; tune for sequences, abnormal hosts, unusual users, rare parent processes, and execution after suspected initial access.
  • Validate detection of obfuscated commands and PowerShell execution rather than only known hashes or tool names, because related frameworks can be publicly available or modified.
  • Correlate RDP activity with valid-account risk indicators such as unusual source/destination pairs, first-time administrative access, off-hours use, and follow-on discovery or credential access.
  • Test visibility into scheduled task and BITSAdmin usage, since both can blend with legitimate Windows administration.
  • Ensure DNS and egress monitoring can support investigation of DnsSystem-like backdoor behavior without assuming DNS traffic is benign.

Mitigation priorities

  • Harden identity first: enforce strong authentication for remote access, reduce standing administrative privilege, and review accounts permitted to use RDP.
  • Reduce lateral movement paths through segmentation, especially between user networks, server environments, and critical service-provider or operationally sensitive systems.
  • Enable and retain endpoint, PowerShell, authentication, DNS, and network telemetry needed to investigate the mapped behaviors.
  • Constrain and monitor administrative utilities such as PowerShell, BITSAdmin, Task Scheduler, and RDP according to business need.
  • Apply credential-protection practices and rapid credential rotation procedures for suspected credential dumping or keylogging incidents.
Additional notes and limits

The strongest decision-useful signal in the supplied ATT&CK data is the combination of targeted critical sectors/geographies and relationships to credential dumping, discovery, RDP, PowerShell, scheduled tasks, BITSAdmin, and multiple Windows backdoors. The group is also associated with aliases Lyceum, Siamesekitten, and Spirlin. Similarity to APT33 and OilRig is noted by ATT&CK, but the supplied description says HEXANE is tracked separately due to differences in victims and tools.

ATT&CK does not provide official detection guidance, group-level platforms, or group-level tactics for this object. Relationship descriptions include platform details for related tools and techniques, but they do not prove activity in any specific local environment. This take should be used to prioritize validation and hunting, not to assert current exploitation, attribution, or confirmed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

HEXANE

HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.CitationDragos HexaneCitationKaspersky Lyceum October 2021CitationClearSky Siamesekitten August 2021CitationAccenture Lyceum Targets November 2021

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.3
Created
Modified
Raw hash
00d73bce12efb77a...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.