Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1001
MITRE ATT&CK Group

HEXANE (G1001)

LyceumSiamesekittenSpirlin
ShareXLinkedInRedditHN

[HEXANE](https://attack.mitre.org/groups/G1001) is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. [HEXANE](https://attack.mitre.org/groups/G1001)'s TTPs appear similar to [APT33](https://attack.mitre.org/groups/G0064) and [OilRig](https://attack.mitre.org/groups/G0049) but due to differences in victims and tools it is tracked as a separate entity.(Citation: Dragos Hexane)(Citation: Kaspersky Lyceum October 2021)(Citation: ClearSky Siamesekitten August 2021)(Citation: Accenture Lyceum Targets November 2021)

▪Techniques used (36)

T1016System Network Configuration DiscoveryT1555Credentials from Password StoresT1027.010Command ObfuscationT1589Gather Victim Identity InformationT1082System Information DiscoveryT1583.001DomainsT1110Brute ForceT1053.005Scheduled TaskT1204.002Malicious FileT1567.002Exfiltration to Cloud StorageT1585.001Social Media AccountsT1016.001Internet Connection DiscoveryT1546.003Windows Management Instrumentation Event SubscriptionT1069.001Local GroupsT1018Remote System DiscoveryT1021.001Remote Desktop ProtocolT1586.002Email AccountsT1110.003Password SprayingT1102.002Bidirectional CommunicationT1588.002ToolT1555.003Credentials from Web BrowsersT1059.001PowerShellT1608.001Upload MalwareT1589.002Email AddressesT1585.002Email AccountsT1033System Owner/User DiscoveryT1105Ingress Tool TransferT1049System Network Connections DiscoveryT1057Process DiscoveryT1056.001KeyloggingT1518Software DiscoveryT1059.005Visual BasicT1010Application Window DiscoveryT1591.004Identify RolesT1583.002DNS ServerT1534Internal Spearphishing

▪Software used (12)

S1015MilanmalwareS0097PingtoolS0104netstattoolS0190BITSAdmintoolS1019SharkmalwareS1021DnsSystemmalwareS1014DanBotmalwareS0363EmpiretoolS0100ipconfigtoolS0002MimikatztoolS1020KevinmalwareS0378PoshC2tool
G1001on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.