Milan is a Windows backdoor associated with the Iranian threat cluster tracked as Lyceum, Hexane, and SiameseKitten, and linked in broader reporting to OilRig activity. It was used in espionage operations targeting organizations in the Middle East, including Israeli IT and communications companies, with indications of supply-chain-oriented objectives. By mid-2021 it was observed being replaced in some intrusion waves by the newer Shark backdoor, while remaining part of the same evolving malware ecosystem alongside DanBot and Marlin.
Milan supports host profiling, command execution, persistence, and file transfer. Observed behavior includes identifying registered users on a compromised machine, discovering local accounts through command execution, and querying the Windows MachineGuid for host identification. It can establish persistence through scheduled tasks, including use of COM-based task creation. Milan also stages files locally before upload and can exfiltrate files from infected hosts. Command-and-control communications have been observed over both HTTP/S and DNS tunneling, and the malware can use hardcoded domains as input to a domain generation algorithm. Operators also used benign-looking naming to reduce suspicion during execution.
Known intrusion chains delivering Milan relied on spearphishing and social-engineering lures, including recruiter impersonation, fake job offers, phishing websites, and malicious lure files. Victim sectors publicly associated with these operations include diplomatic, technology, medical, IT, and communications organizations, particularly in Israel, Tunisia, and the United Arab Emirates.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Lyceum infection chains are also notable for the fact that they have evolved to drop multiple backdoors since the campaign came to light in 2018 — beginning with DanBot and transitioning to Shark and Milan in 2021...
Major tools we attribute to Lyceum include DanBot, the Shark, Milan, and Marlin backdoors...
21 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
Command and Scripting Interpreter: Visual Basic – T1059. Siamesekitten uses a malicious office Macro written in Visual Basic to install the malware.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
The victim is contacted through social media. In this instance, the profile is impersonating a manager from ChipPc’s HR department... The victim is then directed to a website that is embedded with malware and is designed to impersonate the company’s legitimate website.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Initially, HTTP requests are sent to the C&C domain to download a malicious payload.
Application Layer Protocol: DNS – T107.004. Siamesekitten uses DNS Tunneling to communicate with the malware.
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor attributed to the Lyceum subgroup within OilRig, mentioned in the context of subgroup tooling.
Backdoor attributed to Lyceum/OilRig; mentioned as part of the toolset (no further technical detail here).
Backdoor that can identify users registered to a targeted machine.
A Lyceum backdoor introduced in 2021 as part of the campaign's evolving toolset.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.