LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1001: HEXANE

HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.[1][2][3][4]

EnterpriseG1001GroupObject v2.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G1001: HEXANE describes [HEXANE](https://attack.mitre.org/groups/G1001) is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. [HEXANE](https://attack.mitre.org/groups/G1001)'s TTPs appear similar to [APT33](https://attack.mitre.org/groups/G0064) and [OilRig](https://attack.mitre.org/groups/G0049) but due to d...

Executive priority

G1001: HEXANE is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G1001: HEXANE by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G1001: HEXANE appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

HEXANE

HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.[1][2][3][4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

36 rows
DomainIDNameRelationship / procedure
EnterpriseT1016System Network Configuration Discovery

HEXANE has used Ping and `tracert` for network discovery.[2]

EnterpriseT1555Credentials from Password Stores

HEXANE has run `cmdkey` on victim machines to identify stored credentials.[2]

EnterpriseT1027.010Command ObfuscationSub-technique

HEXANE has used Base64-encoded scripts.[2]

EnterpriseT1589Gather Victim Identity Information

HEXANE has identified specific potential victims at targeted organizations.[3]

EnterpriseT1082System Information Discovery

HEXANE has collected the hostname of a compromised machine.[2]

EnterpriseT1583.001DomainsSub-technique

HEXANE has registered and operated domains for campaigns, often using a security or web technology theme or impersonating the targeted organization.[5][1][3]

EnterpriseT1110Brute Force

HEXANE has used brute force attacks to compromise valid credentials.[5]

EnterpriseT1053.005Scheduled TaskSub-technique

HEXANE has used a scheduled task to establish persistence for a keylogger.[2]

EnterpriseT1204.002Malicious FileSub-technique

HEXANE has relied on victim's executing malicious file attachments delivered via email or embedded within actor-controlled websites to deliver malware.[5][1][3]CitationZscaler Lyceum DnsSystem June 2022

EnterpriseT1567.002Exfiltration to Cloud StorageSub-technique

HEXANE has used cloud services, including OneDrive, for data exfiltration.CitationMicrosoft POLONIUM June 2022

EnterpriseT1585.001Social Media AccountsSub-technique

HEXANE has established fraudulent LinkedIn accounts impersonating HR department employees to target potential victims with fake job offers.[3]

EnterpriseT1016.001Internet Connection DiscoverySub-technique

HEXANE has used tools including BITSAdmin to test internet connectivity from compromised hosts.[2]

EnterpriseT1546.003Windows Management Instrumentation Event SubscriptionSub-technique

HEXANE has used WMI event subscriptions for persistence.[2]

EnterpriseT1069.001Local GroupsSub-technique

HEXANE has run `net localgroup` to enumerate local groups.[2]

EnterpriseT1018Remote System Discovery

HEXANE has used `net view` to enumerate domain machines.[2]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

HEXANE has used remote desktop sessions for lateral movement.[5]

EnterpriseT1586.002Email AccountsSub-technique

HEXANE has used compromised accounts to send spearphishing emails.[5]

EnterpriseT1110.003Password SprayingSub-technique

HEXANE has used password spraying attacks to obtain valid credentials.[5]

EnterpriseT1102.002Bidirectional CommunicationSub-technique

HEXANE has used cloud services, including OneDrive, for C2.CitationMicrosoft POLONIUM June 2022

EnterpriseT1588.002ToolSub-technique

HEXANE has acquired, and sometimes customized, open source tools such as Mimikatz, Empire, VNC remote access software, and DIG.net.[2][5]CitationZscaler Lyceum DnsSystem June 2022

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

HEXANE has used a Mimikatz-based tool and a PowerShell script to steal passwords from Google Chrome.[2]

EnterpriseT1059.001PowerShellSub-technique

HEXANE has used PowerShell-based tools and scripts for discovery and collection on compromised hosts.[5]CitationKaspersky APT Trends Q1 April 2021[2]

EnterpriseT1608.001Upload MalwareSub-technique

HEXANE has staged malware on fraudulent websites set up to impersonate targeted organizations.[3]

EnterpriseT1589.002Email AddressesSub-technique

HEXANE has targeted executives, human resources staff, and IT personnel for spearphishing.[5][3]

EnterpriseT1585.002Email AccountsSub-technique

HEXANE has established email accounts for use in domain registration including for ProtonMail addresses.[2]

EnterpriseT1033System Owner/User Discovery

HEXANE has run `whoami` on compromised machines to identify the current user.[2]

EnterpriseT1105Ingress Tool Transfer

HEXANE has downloaded additional payloads and malicious scripts onto a compromised host.[2]

EnterpriseT1049System Network Connections Discovery

HEXANE has used netstat to monitor connections to specific ports.[2]

EnterpriseT1057Process Discovery

HEXANE has enumerated processes on targeted systems.[2]

EnterpriseT1056.001KeyloggingSub-technique

HEXANE has used a PowerShell-based keylogger named `kl.ps1`.[5][2]

EnterpriseT1518Software Discovery

HEXANE has enumerated programs installed on an infected machine.[2]

EnterpriseT1059.005Visual BasicSub-technique

HEXANE has used a VisualBasic script named `MicrosoftUpdator.vbs` for execution of a PowerShell keylogger.[2]

EnterpriseT1010Application Window Discovery

HEXANE has used a PowerShell-based keylogging tool to capture the window title.[5]

EnterpriseT1591.004Identify RolesSub-technique

HEXANE has identified executives, HR, and IT staff at victim organizations for further targeting.[5][3]

EnterpriseT1583.002DNS ServerSub-technique

HEXANE has set up custom DNS servers to send commands to compromised hosts via TXT records.CitationZscaler Lyceum DnsSystem June 2022

EnterpriseT1534Internal Spearphishing

HEXANE has conducted internal spearphishing attacks against executives, HR, and IT personnel to gain information and access.[5]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0097: Ping

Ping is an operating system utility commonly used to troubleshoot and verify network connections. [1]

ToolEnterprise

S0104: netstat

netstat is an operating system utility that displays active TCP connections, listening ports, and network statistics. [1]

MalwareEnterprise

S1021: DnsSystem

DnsSystem is a .NET based DNS backdoor, which is a customized version of the open source tool DIG.net, that has been used by HEXANE since at least June 2022.[1]

Windows
ToolEnterprise

S0363: Empire

Empire is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python, the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries.[1][2][3]

LinuxmacOSWindows
ToolEnterprise

S0100: ipconfig

ipconfig is a Windows utility that can be used to find information about a system's TCP/IP, DNS, DHCP, and adapter configuration. [1]

ToolEnterprise

S0002: Mimikatz

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. [1] [2]

Windows
MalwareEnterprise

S1020: Kevin

Kevin is a backdoor implant written in C++ that has been used by HEXANE since at least June 2020, including in operations against organizations in Tunisia.[1]

Windows
ToolEnterprise

S0378: PoshC2

PoshC2 is an open source remote administration and post-exploitation framework that is publicly available on GitHub. The server-side components of the tool are primarily written in Python, while the implants are written in PowerShell. Although PoshC2 is primarily focused on Windows implantation, it does contain a basic Python dropper for Linux/macOS.[1]

WindowsLinuxmacOS
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
2.3
Created
Modified
Raw hash
336c774d875084ed...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.22.3Current bundle336c774d8750…
19.12.3Older bundle00d73bce12ef…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Dragos Hexane

    Dragos. (n.d.). Hexane. Retrieved October 27, 2019.

    Open source URL
  2. [2]
    Kaspersky Lyceum October 2021

    Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022.

    Open source URL
  3. [3]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
  4. [4]
    Accenture Lyceum Targets November 2021

    Accenture. (2021, November 9). Who are latest targets of cyber group Lyceum?. Retrieved June 16, 2022.

    Open source URL
  5. [5]
    SecureWorks August 2019

    SecureWorks 2019, August 27 LYCEUM Takes Center Stage in Middle East Campaign Retrieved. 2019/11/19

    Open source URL
  6. [6]
    Lyceum

    (Citation: SecureWorks August 2019)

  7. [7]
    Siamesekitten

    (Citation: ClearSky Siamesekitten August 2021)

  8. [8]
    Spirlin

    (Citation: Accenture Lyceum Targets November 2021)

  9. [9]
    mitre-attackG1001
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.