Major tools we attribute to Lyceum include DanBot, the Shark, Milan, and Marlin backdoors...
DanBot
DanBot is a backdoor associated with the Lyceum threat group.
Profile source: Mallory opens in a new tabDanBot
Family profile
DanBot is a backdoor associated with the Lyceum threat group. It has been delivered via spearphishing emails containing malicious Excel attachments and relies on victim interaction to execute, including opening the malicious file. The malware can use a VBA macro embedded in an Excel file to drop its payload and can establish installation or persistence through a scheduled task. DanBot samples have been named UltraVNC.exe and WINVNC.exe to masquerade as legitimate VNC tools. Reported capabilities include uploading files from compromised hosts. The provided content identifies DanBot as one of the major tools attributed to Lyceum, alongside the Shark, Milan, and Marlin backdoors.
Reported operators
Threat actors
2 named in public reportingMajor tools we attribute to Lyceum include DanBot, the Shark, Milan, and Marlin backdoors...
MITRE ATT&CK
DanBot in ATT&CK
19 distinct techniquesTechniques
19 techniquesReporting
Research mentioning DanBot
BladedFeline: Whispering in the dark
Major tools we attribute to Lyceum include DanBot, the Shark, Milan, and Marlin backdoors...
OilRig’s persistent attacks using cloud service-powered downloaders
Major tools we attribute to Lyceum include DanBot, the Shark, Milan, and Marlin backdoors...
User Execution: Malicious File, Sub-technique T1204.002 - Enterprise | MITRE ATT&CK®
DanBot has relied on victims' opening a malicious file for initial execution.
Scheduled Task/Job: Scheduled Task, Sub-technique T1053.005 - Enterprise | MITRE ATT&CK®
DanBot can use a scheduled task for installation.
Command and Scripting Interpreter: Visual Basic, Sub-technique T1059.005 - Enterprise | MITRE ATT&CK®
DanBot can use a VBA macro embedded in an Excel file to drop the payload.
User Execution: Malicious File, Sub-technique T1204.002 - Enterprise | MITRE ATT&CK®
DanBot has relied on victims' opening a malicious file for initial execution.
Phishing: Spearphishing Attachment, Sub-technique T1566.001 - Enterprise | MITRE ATT&CK®
DanBot has been distributed within a malicious Excel attachment via spearphishing emails.