COBALT LYCEUM is an Iranian state-sponsored threat actor associated with cyber operations against critical infrastructure and government-related targets. Reported targeting includes telecommunications, oil and gas, and government entities. The group has been linked to tradecraft involving exploitation of internet-facing enterprise applications, deployment of web shells, long-term persistence, credential abuse, and post-compromise access maintenance across multiple servers. Activity associated with Iranian operators overlapping this cluster has included use of malicious IIS modules and web shells on Microsoft Exchange and SharePoint environments, reuse of compromised administrator credentials, and establishment of multiple footholds to survive remediation. Observed behaviors include remote code execution through server-side implants, credential dumping, exfiltration of stolen data, and use of native administrative tooling for defense evasion and persistence. COBALT LYCEUM has also been associated with RGDoor-related tradecraft, including abuse of IIS administration utilities to install malicious components. The actor is part of the broader Iranian intrusion ecosystem and is tracked alongside other Iran-linked clusters such as COBALT GYPSY. While some intrusion reporting has noted similarities between certain Exchange and SharePoint compromises and Iranian tradecraft, specific attribution in those cases has at times remained only moderate-confidence. High-confidence reporting identifies COBALT LYCEUM as an Iranian group known for targeting critical infrastructure organizations and government entities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another Iranian group that used similar IIS-module installation techniques and RGDoor-related tradecraft.
Iranian state-sponsored espionage targeting critical infrastructure and government entities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.