Threat group.View on attack.mitre.org
HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.
| Technique | Procedure example |
|---|---|
| T1010 Application Window Discovery |
HEXANE has used a PowerShell-based keylogging tool to capture the window title. |
| T1016 System Network Configuration Discovery |
|
| T1016.001 Internet Connection Discovery |
HEXANE has used tools including BITSAdmin to test internet connectivity from compromised hosts. |
| T1018 Remote System Discovery |
HEXANE has used `net view` to enumerate domain machines. |
| T1021.001 Remote Desktop Protocol |
HEXANE has used remote desktop sessions for lateral movement. |
| T1027.010 Command Obfuscation |
HEXANE has used Base64-encoded scripts. |
| T1033 System Owner/User Discovery |
HEXANE has run `whoami` on compromised machines to identify the current user. |
| T1049 System Network Connections Discovery |
HEXANE has used netstat to monitor connections to specific ports. |
| T1053.005 Scheduled Task |
HEXANE has used a scheduled task to establish persistence for a keylogger. |
| T1056.001 Keylogging |
HEXANE has used a PowerShell-based keylogger named `kl.ps1`. |
| T1057 Process Discovery |
HEXANE has enumerated processes on targeted systems. |
| T1059.001 PowerShell |
HEXANE has used PowerShell-based tools and scripts for discovery and collection on compromised hosts. |
| T1059.005 Visual Basic |
HEXANE has used a VisualBasic script named `MicrosoftUpdator.vbs` for execution of a PowerShell keylogger. |
| T1069.001 Local Groups |
HEXANE has run `net localgroup` to enumerate local groups. |
| T1082 System Information Discovery |
HEXANE has collected the hostname of a compromised machine. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.