LYCEUM threat group takes centre stage in Middle East
Last Update: Tuesday, September 3, 2019 : 14:16 (+4GMT)
The previously unobserved LYCEUM threat group targeted critical infrastructure organisations without being detected for more than 12 months
Dubai, United Arab Emirates - September 03, 2019: The LYCEUM threat group targets organisations in sectors of strategic national importance, including oil and gas and possibly telecommunications. The activity observed by Secureworks® Counter Threat Unit™ (CTU) researchers focuses on obtaining and expanding access within a targeted network.
CTU™ research indicates that LYCEUM may have been active as early as April 2018. Domain registrations suggest that a campaign in mid-2018 focused on South African targets. In May 2019, the threat group launched a campaign against oil and gas organisations in the Middle East. This campaign followed a sharp uptick in development and testing of their toolkit against a public multi-vendor malware scanning service in February 2019.
Stylistically, the observed tradecraft resembles activity from groups such as COBALT GYPSY (which is related to OilRig, Crambus, and APT34) and COBALT TRINITY (also known as Elfin and APT33). However, none of the collected malware or infrastructure associated with LYCEUM has direct links to observed activity from these or other known threat groups. As of this publication, there is insufficient technical evidence to support an attribution assessment.
When CTU researchers first published information about LYCEUM to Secureworks Threat Intelligence clients, no public documentation on the group existed. Since then, reporting has emerged that refers to the threat group as HEXANE.
The LYCEUM toolkit
LYCEUM initially accesses an organisation using account credentials obtained via password spraying or brute-force attacks. Using compromised accounts, the threat actors send spearphishing emails with malicious Excel attachments to deliver the DanBot malware, which subsequently deploys post-intrusion tools.
CTU researchers have observed LYCEUM using the following tools:
• DanBot — A first-stage remote access trojan (RAT) that uses DNS and HTTP-based communication mechanisms and provides basic remote access capability, including the abilities to execute arbitrary commands via cmd.exe and to upload and download files
• DanDrop — A VBA macro embedded in an Excel XLS file used to drop DanBot
• kl.ps1 — A PowerShell-based keylogger
• Decrypt-RDCMan.ps1 — Part of the PoshC2 framework
• Get-LAPSP.ps1 — A PowerView-based script from the PowerShell Empire framework
Conclusion
LYCEUM is an emerging threat to energy organisations in the Middle East, but organisations should not assume that future targeting will be limited to this sector. Critical infrastructure organisations in particular should take note of the threat group’s tradecraft. Aside from deploying novel malware, LYCEUM’s activity demonstrates capabilities CTU researchers have observed from other threat groups and reinforces the value of a few key controls.
Password spraying, DNS tunneling, social engineering, and abuse of security testing frameworks are common tactics, particularly from threat groups operating in the Middle East.
While there are many security controls that could mitigate aspects of a LYCEUM intrusion, CTU researchers recommend the following to provide broad protection and detection capabilities that apply to a spectrum of threats:
• Implement multi-factor authentication (MFA)
• Increase visibility via endpoint detection, response, and logging
• Conduct preparedness exercises including Incident response and phishing awareness
Previous Article
Region's Hvac Industry Meets in Dubai to Plan Path to Sustainabil...
Next Article
ThreatQuotient Set to Make its Debut at MENA ISC 2019
Most Viewed – Last 30 Days
- From a Pair of Shoes to a New Dubai Property: British Expat Wins Through ‘Win ... [3006-Views]
- UAQ Free Zone and Port City Colombo Sign Agreement to Promote Investment ... [1973-Views]
- Sheikh Zayed Falcon Release Programme releases 2,400+ falcons in the wild sinc... [1823-Views]
- DSS FINAL SALE BRINGS UP TO 90% OFF ACROSS MORE THAN 500 BRANDS FOR THE FINAL ... [1553-Views]
- President of the Comoros H.E. Azali Assoumani inaugurates UAE-financed solar p... [1517-Views]
- Environment Agency - Abu Dhabi partners with Japan’s Suwa Falconry Preservatio... [1513-Views]
- e& UAE launches Business Pro AI bundled with Microsoft Copilot at no additiona... [1412-Views]
- Held under the patronage of His Highness Sheikh Hamdan bin Zayed Al Nahyan Ab... [1187-Views]
- Beautyworld Dubai's 30th Edition Brings Global BeautyIcons Together This Octob... [1183-Views]
- Tadej Pogacar Chases Tour de France–Vuelta a Espana Double... [1143-Views]
- In a first-of-its-kind experience for a private Emirati company Hattlan Media... [1110-Views]
- "A Dubai Invite" programme concludes following more than 90,000 applications f... [1087-Views]
- Al Habtoor Motors launches ‘Back to School with Mitsubishi’ offers with Buy No... [1037-Views]
- Stellar Wine Cellar: Emirates to serve exceptional Champagnes and fine wines o... [1015-Views]
- Salik Renews Strategic Partnership for Five Years to Support Tolling System an... [975-Views]
- LG Empowers Designers and Videographers with New Ultrafine Evo 6K Monitor... [966-Views]
- President of Senegal Receives HE Al Zeyoudi in Dakar to Discuss Expanding Trad... [904-Views]
- ‘Win Your Home in Dubai’ Concludes Landmark Citywide Initiative, Driving More ... [867-Views]
- Abu Dhabi Student’s AI Triage Platform That Guides Patients to Right Care Wins... [851-Views]
- Isaac del Toro lands overall title at the Lidl Deutschland Tour... [809-Views]





