Lyceum, also known as Hexane, SiameseKitten, Spirlin, and Storm-0133, is an Iranian state-linked cyber-espionage threat actor commonly assessed as operating on behalf of Iran’s Ministry of Intelligence and Security (MOIS). The group is widely regarded as a sub-group or affiliated cluster within the broader OilRig ecosystem. Its operations have focused primarily on espionage, with targeting that has included government entities, critical infrastructure, telecommunications, energy, and IT providers, particularly in the Middle East and with repeated reporting around Israeli interests. Lyceum is known for targeted intrusion activity, credential theft, post-compromise reconnaissance, and modular malware development. Reported tradecraft includes spearphishing and other user-execution vectors for initial access, staging malware on fraudulent websites impersonating targeted organizations, and use of PowerShell during execution. On compromised systems, the group has been observed collecting host information such as the hostname and current user context, including use of commands such as whoami. The actor has also been associated with modular .NET malware and plugin-loading approaches consistent with long-term espionage operations. Recent reporting has highlighted technical overlaps between Lyceum and other Iranian intrusion activity, including MuddyWater and the MOIS-linked cluster tracked as Cavern Manticore. Lyceum has been cited as having similarities in modular .NET architecture, command structure, and plugin-loading behavior with malware linked to the Cavern framework, although some of these links remain assessed only with low confidence and should not be treated as definitive attribution. Lyceum is therefore best understood as an Iranian espionage actor within the broader constellation of MOIS-aligned operations, sharing tooling and tradecraft patterns with related Iranian threat clusters while maintaining its own tracking identity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 malware families attributed to this actor across reporting.
14 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
71 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Iranian threat group with technical overlaps to the HOLLOWGRAPH activity; the connection is assessed at low confidence.
Iranian threat actor mentioned as a low-confidence overlap with the HollowGraph campaign and as overlapping with Cavern Manticore per prior reporting.
Possible low-confidence attribution overlap with the HOLLOWGRAPH espionage campaign targeting Israeli organizations.
Previously associated with malware overlapping with HOLLOWGRAPH/Cavern; mentioned as a possible low-confidence link to the observed espionage activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.