Major tools we attribute to Lyceum include DanBot, the Shark, Milan, and Marlin backdoors...
DanBot
DanBot is a backdoor associated with the Lyceum threat group.
Profile source: Mallory opens in a new tabDanBot
Family profile
DanBot is a backdoor associated with the Lyceum threat group. It has been delivered via spearphishing emails containing malicious Excel attachments and relies on victim interaction to execute, including opening the malicious file. The malware can use a VBA macro embedded in an Excel file to drop its payload and can establish installation or persistence through a scheduled task. DanBot samples have been named UltraVNC.exe and WINVNC.exe to masquerade as legitimate VNC tools. Reported capabilities include uploading files from compromised hosts. The provided content identifies DanBot as one of the major tools attributed to Lyceum, alongside the Shark, Milan, and Marlin backdoors.
Reported operators
Threat actors
2 named in public reportingMajor tools we attribute to Lyceum include DanBot, the Shark, Milan, and Marlin backdoors...
MITRE ATT&CK