LYCEUM is an Iranian nation-state cyber espionage group targeting government and energy sectors in the Middle East.
Analyst brief
LYCEUM is an Iranian nation-state APT group active since at least 2014, primarily conducting cyber espionage against government, energy, high-tech, telecom, education, military, and defense sectors in Israel and the Middle East. They gain initial access via malicious files, leverage tools like Mimikatz, Empire, and PoshC2 for credential theft, move laterally using RDP, and establish C2 communication through DNS tunneling and HTTP. Defenders should focus on detecting phishing emails, anomalous scheduled tasks, suspicious DNS queries, and known IOCs for their malware families such as Shark, Milan, and DanBot.
LYCEUM
COBALT LYCEUMHEXANEUNC1530
nation-state
Lyceum is an Iranian APT group that has been active since at least 2014. They primarily target Middle Eastern governments and organizations in the energy and telecommunications sectors. Lyceum is known for using cyber espionage techniques and has been linked to other Iranian threat groups such as APT34. They have developed and deployed malware families like Shark and Milan, and have been observed using DNS tunneling and HTTPfor command and control communication.
origin (suspected)
🇮🇷Iran· state-sponsoredattribution confidence: medium (50)