← Back to all threat actors

HEXANE

Also known as Lyceum, Siamesekitten, Spirlin
Tracked as G1001

HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.

How we source and review actor profiles
Motivation
nation-state
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: Lyceum

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Siamesekitten

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Spirlin

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G1001

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

HEXANECanonical Name
LyceumAlias
SiamesekittenAlias
SpirlinAlias
G1001Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...