Threat Actor ๐Ÿ‡ฎ๐Ÿ‡ท Iran

LYCEUM

Also known as: COBALT LYCEUM ยท HEXANE ยท UNC1530 ยท Spirlin ยท MYSTICDOME ยท siamesekitten ยท Chrono Kitten ยท Storm-0133

Lyceum is an Iranian APT group that has been active since at least 2014. They primarily target Middle Eastern governments and organizations in the energy and telecommunications sectors. Lyceum is known for using cyber espionage techniques and has been linked to other Iranian threat groups such as APT34. They have developed and deployed malware families like Shark and Milan, and have been observed using DNS tunneling and HTTPfor command and control communication.

Indicators of Compromise 10

MITRE ATT&CK TTPs 13

Source Articles

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
HollowGraph is a newly discovered espionage malware that leverages a compromised Microsoft 365 calendar as a covert command-and-control (C2) channel, hiding operator instructions and exfiltrated data within calendar events dated to 2050. The malware uses legitimate Microsoft Graph API traffic to avoid detection, communicating via encrypted attachments on future-dated events. It is associated with the Cavern backdoor framework and shows potential ties to Iranian-linked actors, though attribution remains unconfirmed. The small, targeted footprint suggests focused cyber espionage rather than broad criminal activity.
hacker-news ยท1w ago
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
A newly identified malware named HollowGraph leverages compromised Microsoft 365 accounts and the Microsoft Graph API for command-and-control (C2) communications, using calendar events as a covert channel to send and receive encrypted commands and exfiltrated data. The malware is associated with the Cavern C2 framework and shows technical similarities to the Iranian-linked threat actor Lyceum, though attribution remains unconfirmed. HollowGraph employs hybrid encryption (RSA and AES-256-GCM), DNS tunneling for credential updates, and targets organizations in Israel for espionage purposes.
bleeping-computer ยท1w ago
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
An Iranian hacking group linked to the Ministry of Intelligence and Security (MOIS), tracked as Cavern Manticore, has been using a new modular command-and-control (C2) framework named Cavern to target Israeli organizations, particularly in the IT and government sectors. The attack leverages DLL side-loading via SysAid's software update mechanism, deploying a trojanized DLL (uxtheme.dll) that communicates with a C2 server and downloads additional malicious modules. These modules enable reconnaissance, data theft, lateral movement, and tunneling, with a sophisticated .NET-based architecture using mixed compilation formats to hinder analysis. The group exploits trusted relationships in the software supply chain and has shifted from broad reconnaissance to targeted data exfiltration across Middle Eastern sectors.
hacker-news ยท3w ago