THREAT_ACTOR · G1011
EXOTIC LILY
Also known as: EXOTIC LILY
Profile
EXOTIC LILY is a financially motivated group that has been closely linked with Wizard Spider and the deployment of ransomware including Conti and Diavol. EXOTIC LILY may be acting as an initial access broker for other malicious actors, and has targeted a wide range of industries including IT, cybersecurity, and healthcare since at least September 2021.
MITRE ATT&CK ↗Techniques
15 ATT&CK techniques attributed to this actor.
T1102 Web ServiceT1203 Exploitation for Client ExecutionT1204.001 Malicious LinkT1204.002 Malicious FileT1566.001 Spearphishing AttachmentT1566.002 Spearphishing LinkT1566.003 Spearphishing via ServiceT1583.001 DomainsT1585.001 Social Media AccountsT1585.002 Email AccountsT1589.002 Email AddressesT1593.001 Social MediaT1594 Search Victim-Owned WebsitesT1597 Search Closed SourcesT1608.001 Upload Malware
Software
2 malware/tools attributed to this actor.
BazarBumblebee
Related corpus activity
8,744 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to EXOTIC LILY.
Showing the top 30 by severity of 8,744.