Skip to content

DanBot

DanBot is a Windows remote access trojan and backdoor associated with the Iranian espionage cluster tracked as Lyceum, also known as Hexane and SiameseKitten, and linked by multiple researchers to OilRig/APT34 activity.

Profile source: Mallory opens in a new tab

DanBot

Family profile

DanBot is a Windows remote access trojan and backdoor associated with the Iranian espionage cluster tracked as Lyceum, also known as Hexane and SiameseKitten, and linked by multiple researchers to OilRig/APT34 activity. It appeared in Lyceum intrusion chains from at least 2018 and was later supplemented or replaced in some operations by the Shark, Milan, and Marlin backdoors. DanBot has been used in cyberespionage campaigns targeting organizations in the Middle East, including diplomatic, technology, medical, IT, and communications sectors, with notable victimology in Israel, Tunisia, and the United Arab Emirates.

DanBot has commonly been delivered through spearphishing emails carrying malicious Excel attachments. These lures relied on user execution and embedded VBA macros to drop the payload onto the victim system. The malware has also been observed establishing persistence through Windows Scheduled Tasks. In addition to masquerading as legitimate remote administration software, DanBot samples have used names intended to resemble VNC utilities, consistent with defense-evasion tradecraft.

Functionally, DanBot provides remote access capabilities and has been observed uploading files from compromised hosts, supporting post-compromise collection and exfiltration workflows. Reporting on related Lyceum tooling indicates overlapping design and operational patterns across the group’s backdoors, including similar command execution behavior and shared implementation artifacts, placing DanBot within a broader long-running Iranian cyberespionage ecosystem focused on persistent access and intelligence collection.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Persistence
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 24, 2026
Last activity
Sep 26, 2026
Feed role
C2
Host form
4 IP / 0 hostnames

Leading locations

  • BR2
  • DE1
  • HR1

Leading providers

  • Netvox Telecomunicacoes LTDA2
  • A1 Hrvatska d.o.o.1
  • Oracle Corporation1

Infrastructure traits

  • Hosting 1

Reported operators

Threat actors

2 named in public reporting
HEXANE

The Lyceum infection chains are also notable for the fact that they have evolved to drop multiple backdoors since the campaign came to light in 2018 β€” beginning with DanBot and transitioning to Shark and Milan in 2021...

OilRig

Major tools we attribute to Lyceum include DanBot, the Shark, Milan, and Marlin backdoors...

MITRE ATT&CK

DanBot in ATT&CK

20 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.