Lyceum
MITRE G0839Also known as OilRig subgroup, HEXANE, Storm-0133
Reports
3
First seen
Dec 2, 2025
Last seen
Jul 6, 2026
Motivation
Espionage
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
×2×2
Israel×2
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1566.002 Phishing: Spearphishing Link ×2T1195 Supply Chain Compromise ×2T1219 Remote Access Software ×2T1087 Account Discovery ×1T1561 Disk Wipe ×1T1498 Network Denial of Service ×1T1083 File and Directory Discovery ×1T1566.001 Phishing: Spearphishing Attachment ×1T1059.001 Command and Scripting Interpreter: PowerShell ×1T1620 Reflective Code Loading ×1T1021.002 Remote Services (SMB/Windows Admin Shares) ×1T1110 Brute Force ×1
Indicators
filename ×28ip_v4 ×11cve ×5hash_sha256 ×4registry_key ×3domain ×3hash_md5 ×2url ×1hash_sha1 ×1
Indicator values are available on Pro and via the API.
Associated CVEs
Recent reports
High