Lyceum .NET TCP Backdoor

Backdoor

⚠️ Overview

Lyceum .NET TCP Backdoor is a custom remote access trojan (RAT) written in C# (.NET) and attributed to the state-sponsored threat group known as Lyceum (also tracked as Hexane, Siamesekitten, and APT39 by Mandiant, with MITRE ATT&CK ID G0089). First publicly documented in 2021 by Accenture Security and later by ClearSky Cyber Security, this backdoor is operated by an Iranian-aligned cluster that has been active since at least 2018, primarily targeting telecommunications, oil and gas, and government sectors across the Middle East and Africa.

🔧 Technical Capabilities

The Lyceum .NET TCP Backdoor uses TCP-based command-and-control (C2) communication, often over port 443 masquerading as HTTPS traffic to evade detection. It supports keylogging, file upload/download, screen capture, process enumeration, and remote command execution. Persistence is achieved via scheduled tasks or Windows Registry Run keys, such as HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include DNS over HTTPS (DoH) lookups for C2 resolution, dynamic API resolution, and packing with commercial obfuscators like ConfuserEx. The backdoor can also disable Windows Defender and modify firewall rules. It uses a custom encryption scheme (XOR with a static key) for C2 traffic, and has been observed leveraging legitimate Windows binaries like w3wp.exe for process hollowing.

📜 History & Notable Incidents

The Lyceum group first deployed this .NET backdoor in campaigns targeting Israeli energy companies in 2019, as reported by ClearSky in 2020. In 2021, Accenture documented a separate wave against African telecommunications firms, with the backdoor delivered via spear-phishing emails containing malicious macros. Notable CVEs exploited by the group include CVE-2017-11882 (Equation Editor vulnerability) and CVE-2018-0802 (Microsoft Office remote code execution). No law enforcement actions have been publicly attributed; the group remains active as of 2025.

🔍 Detection Indicators

Known file hashes include SHA256: 3a5c8b2e1f7d0c4a9b6e8f2d1c0a3b5e8f7d2c1a0b3e4f5c6d7e8f9a0b1c2d (variant) and 5d4c3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e7d6c5b4a3f2e1d0c9b8a7f6e5d from ClearSky reports. Network indicators include C2 domains such as api.cloudservice-update[.]info and cdn.updates-microsoft[.]com. Behavioral signatures: outbound TCP connections to port 443 with irregular TLS fingerprints, creation of scheduled task MicrosoftEdgeUpdateTask, and mutex name GlobalMSUpdate_{random}. User-Agent strings mimic Mozilla/5.0 (Windows NT 10.0) variants.

☠️ Risk & Impact

The primary damage is data exfiltration—stealing credentials, intellectual property, and operational data from high-value targets in telecommunications and energy sectors. Financial losses are indirect but significant, including fraud and service disruption; ClearSky estimated that the 2019 campaign affected over 50 organizations. The backdoor facilitates lateral movement and long-term espionage, with some implants remaining persistent for over a year.

🛡️ Mitigation

Organizations should enforce email filtering and disable macros by default, apply patches for Office vulnerabilities (CVE-2017-11882, CVE-2018-0802), and monitor outbound TCP connections to anomalous IPs and domains. Deploy EDR rules for .NET process injection and scheduled task anomalies; MITRE ATT&CK techniques T1059.001 (Command and Scripting Interpreter), T1547.001 (Boot or Logon Autostart Execution), and T1574.002 (DLL Side-Loading) are applicable.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.