Last seven days
- First activity
- Sep 24, 2026
- Last activity
- Sep 26, 2026
- Feed role
- C2
- Host form
- 4 IP / 0 hostnames
DanBot is a Windows remote access trojan and backdoor associated with the Iranian espionage cluster tracked as Lyceum, also known as Hexane and SiameseKitten, and linked by multiple researchers to OilRig/APT34 activity.
Profile source: Mallory opens in a new tabDanBot
DanBot is a Windows remote access trojan and backdoor associated with the Iranian espionage cluster tracked as Lyceum, also known as Hexane and SiameseKitten, and linked by multiple researchers to OilRig/APT34 activity. It appeared in Lyceum intrusion chains from at least 2018 and was later supplemented or replaced in some operations by the Shark, Milan, and Marlin backdoors. DanBot has been used in cyberespionage campaigns targeting organizations in the Middle East, including diplomatic, technology, medical, IT, and communications sectors, with notable victimology in Israel, Tunisia, and the United Arab Emirates.
DanBot has commonly been delivered through spearphishing emails carrying malicious Excel attachments. These lures relied on user execution and embedded VBA macros to drop the payload onto the victim system. The malware has also been observed establishing persistence through Windows Scheduled Tasks. In addition to masquerading as legitimate remote administration software, DanBot samples have used names intended to resemble VNC utilities, consistent with defense-evasion tradecraft.
Functionally, DanBot provides remote access capabilities and has been observed uploading files from compromised hosts, supporting post-compromise collection and exfiltration workflows. Reporting on related Lyceum tooling indicates overlapping design and operational patterns across the groupβs backdoors, including similar command execution behavior and shared implementation artifacts, placing DanBot within a broader long-running Iranian cyberespionage ecosystem focused on persistent access and intelligence collection.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
The Lyceum infection chains are also notable for the fact that they have evolved to drop multiple backdoors since the campaign came to light in 2018 β beginning with DanBot and transitioning to Shark and Milan in 2021...
Major tools we attribute to Lyceum include DanBot, the Shark, Milan, and Marlin backdoors...
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.