Threat Actor ๐ฎ๐ท Iran
LYCEUM
Also known as: COBALT LYCEUM ยท HEXANE ยท UNC1530 ยท Spirlin ยท MYSTICDOME ยท siamesekitten ยท Chrono Kitten ยท Storm-0133
Lyceum is an Iranian APT group that has been active since at least 2014. They primarily target Middle Eastern governments and organizations in the energy and telecommunications sectors. Lyceum is known for using cyber espionage techniques and has been linked to other Iranian threat groups such as APT34. They have developed and deployed malware families like Shark and Milan, and have been observed using DNS tunneling and HTTPfor command and control communication.
Indicators of Compromise 11
MITRE ATT&CK TTPs 17
T1001.002 T1003 T1027 T1059 T1059.001 T1071.001 T1071.004 T1074 T1074.001 T1082 T1090 T1090.003 T1105 T1132.001 T1558.003 T1566 T1588
Steganography
Command And Control
OS Credential Dumping
Credential Access
Obfuscated Files or Information
Defense Evasion
Command and Scripting Interpreter
Execution
PowerShell
Execution
Web Protocols
Command And Control
DNS
Command And Control
Data Staged
Collection
Local Data Staging
Collection
System Information Discovery
Discovery
Proxy
Command And Control
Multi-hop Proxy
Command And Control
Ingress Tool Transfer
Command And Control
Standard Encoding
Command And Control
Kerberoasting
Credential Access
Phishing
Initial Access
Obtain Capabilities
Resource Development
Source Articles
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Iranian nation-state actors linked to Cavern (aka Cav3rn) C2 framework have evolved their infrastructure to blend malicious traffic with legitimate services, using DNS A-record queries to dynamically switch between direct HTTPS and Google Apps Script relays for command-and-control. A new module, HOLLOWGRAPH, abuses Microsoft 365 calendars via the Graph API to exfiltrate data and receive commands, with events scheduled far into the future to avoid detection. The framework uses a modular architecture with components like GoogleService.dll and rnp.dll, leveraging legitimate cloud services to evade perimeter defenses and maintain persistence.
hacker-news ยท2w ago
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
HollowGraph is a newly discovered espionage malware that leverages a compromised Microsoft 365 calendar as a covert command-and-control (C2) channel, hiding operator instructions and exfiltrated data within calendar events dated to 2050. The malware uses legitimate Microsoft Graph API traffic to avoid detection, communicating via encrypted attachments on future-dated events. It is associated with the Cavern backdoor framework and shows potential ties to Iranian-linked actors, though attribution remains unconfirmed. The small, targeted footprint suggests focused cyber espionage rather than broad criminal activity.
hacker-news ยท1mo ago
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
A newly identified malware named HollowGraph leverages compromised Microsoft 365 accounts and the Microsoft Graph API for command-and-control (C2) communications, using calendar events as a covert channel to send and receive encrypted commands and exfiltrated data. The malware is associated with the Cavern C2 framework and shows technical similarities to the Iranian-linked threat actor Lyceum, though attribution remains unconfirmed. HollowGraph employs hybrid encryption (RSA and AES-256-GCM), DNS tunneling for credential updates, and targets organizations in Israel for espionage purposes.
bleeping-computer ยท1mo ago
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
An Iranian hacking group linked to the Ministry of Intelligence and Security (MOIS), tracked as Cavern Manticore, has been using a new modular command-and-control (C2) framework named Cavern to target Israeli organizations, particularly in the IT and government sectors. The attack leverages DLL side-loading via SysAid's software update mechanism, deploying a trojanized DLL (uxtheme.dll) that communicates with a C2 server and downloads additional malicious modules. These modules enable reconnaissance, data theft, lateral movement, and tunneling, with a sophisticated .NET-based architecture using mixed compilation formats to hinder analysis. The group exploits trusted relationships in the software supply chain and has shifted from broad reconnaissance to targeted data exfiltration across Middle Eastern sectors.
hacker-news ยท1mo ago