EXOTIC LILY

MITRE ATT&CK: G1011 View on attack.mitre.org

Aliases: DEV-0413, EXOTIC LILY

First seen
2021-09-01 00:00:00
Primary motivation
financial-gain
Sophistication
expert
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:01:50

Targeted industries: healthcare-and-pharmaceutical technology-and-telecommunications professional-services

Context

EXOTIC LILY is a financially motivated group that has been closely linked with Wizard Spider and the deployment of ransomware including Conti and Diavol. EXOTIC LILY may be acting as an initial access broker for other malicious actors, and has targeted a wide range of industries including IT, cybersecurity, and healthcare since at least September 2021.

Detection coverage

  • 12 YARA rules
  • 86 Sigma rules

Malware & tools used

  • Spearphishing via Service (attack-pattern)
  • Social Media Accounts (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Malicious File (attack-pattern)
  • Email Accounts (attack-pattern)
  • Web Service (attack-pattern)
  • Search Victim-Owned Websites (attack-pattern)
  • Malicious Link (attack-pattern)
  • Search Closed Sources (attack-pattern)
  • Domains (attack-pattern)
  • Social Media (attack-pattern)
  • Email Addresses (attack-pattern)
  • Upload Malware (attack-pattern)
  • Bumblebee (malware)
  • Bazar (malware)

Exploited vulnerabilities

  • CVE-2021-40444 (vulnerability)

Reports & references

  • Microsoft — Analyzing Attacks That Exploit The Mshtml Cve 2021 40444 Vulnerability (report)
  • blog.google — Exposing Initial Access Broker Ties Conti (report)
  • MITRE ATT&CK — G1011 (report)

External references