Skip to content

Malware

Lyceum .NET TCP Backdoor

This .Net written malware is used as backdoor using the http protocol by a state sponsored threat actor.

Lyceum .NET TCP Backdoor is a Windows malware family operated by LYCEUM.

Background

A state-sponsored threat actor uses this .Net-based malware as a backdoor operating over the HTTP protocol. It also provides extra features such as executing commands, taking screenshots, listing files/directories/installed applications, and uploading, downloading, and executing files. Related variants use DNS (.Net), and one is written in Golang.


Source: Malpedia (Fraunhofer FKIE).