Lyceum

☆ pin
MITRE G0839Also known as OilRig subgroup, HEXANE, Storm-0133
Reports
3
First seen
Dec 2, 2025
Last seen
Jul 6, 2026
Motivation
Espionage

Relationships

Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.

Targeting

Victim regions
×2
×2
Israel×2

Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.

Top ATT&CK techniques

T1566.002 Phishing: Spearphishing Link ×2T1195 Supply Chain Compromise ×2T1219 Remote Access Software ×2T1087 Account Discovery ×1T1561 Disk Wipe ×1T1498 Network Denial of Service ×1T1083 File and Directory Discovery ×1T1566.001 Phishing: Spearphishing Attachment ×1T1059.001 Command and Scripting Interpreter: PowerShell ×1T1620 Reflective Code Loading ×1T1021.002 Remote Services (SMB/Windows Admin Shares) ×1T1110 Brute Force ×1

Indicators

filename ×28ip_v4 ×11cve ×5hash_sha256 ×4registry_key ×3domain ×3hash_md5 ×2url ×1hash_sha1 ×1

Indicator values are available on Pro and via the API.

Associated CVEs

Recent reports

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.