LYCEUM is a threat actor attributed to Iran (Islamic Republic of), assessed as espionage-motivated. Its recorded targeting runs to government, energy, high-tech, telecomms and adjacent sectors across 2 countries in the open reporting we hold — Middle East among them.
Across 36 attributed ATT&CK techniques we resolve 9 distinct behaviours — the things they do that a detection can be written against. The two that account for most of their observed tradecraft are discovery command burst on one host and persistence pointing into world-writable staging. Their toolkit is 12 named items: 5 we see only in this actor's reporting and 7 commodity or dual-use. That ratio is the point — the first group is what identifies them, the second is what they share with every other group and with red teams.
For a Gulf defender the relevant line is the victimology: Middle East appear in the reporting behind this record. That is evidence of past targeting, not a forecast, and it is drawn from what vendors chose to publish — an actor working quietly in a market nobody reports on looks identical to one that is absent.
As MITRE describes them: “Lyceum is an Iranian APT group that has been active since at least 2014. They primarily target Middle Eastern governments and organizations in the energy and telecommunications sectors. Lyceum is known for using cyber espionage techniques and has been linked to other Iranian threat groups such as APT34. They have developed and deployed malware families like Shark and Milan, and have been observed using DNS tunneling and HTTPfor command and control communication.” — MITRE ATT&CK, CC BY 4.0.
On the name. “LYCEUM” labels a cluster of related activity tracked under one name — not a verified organisation. Whether one team, several contractors or a rotating cast sits behind it is not something this record establishes, and the vendor names below are separate groupings that only mostly overlap.