EXOTIC LILY
MITRE ATT&CK: G1011 View on attack.mitre.org
Aliases: DEV-0413, EXOTIC LILY
- First seen
- 2021-09-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- expert
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:01:50
Targeted industries: healthcare-and-pharmaceutical technology-and-telecommunications professional-services
Context
EXOTIC LILY is a financially motivated group that has been closely linked with Wizard Spider and the deployment of ransomware including Conti and Diavol. EXOTIC LILY may be acting as an initial access broker for other malicious actors, and has targeted a wide range of industries including IT, cybersecurity, and healthcare since at least September 2021.
Detection coverage
- 12 YARA rules
- 86 Sigma rules
Malware & tools used
- Spearphishing via Service (attack-pattern)
- Social Media Accounts (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Spearphishing Link (attack-pattern)
- Malicious File (attack-pattern)
- Email Accounts (attack-pattern)
- Web Service (attack-pattern)
- Search Victim-Owned Websites (attack-pattern)
- Malicious Link (attack-pattern)
- Search Closed Sources (attack-pattern)
- Domains (attack-pattern)
- Social Media (attack-pattern)
- Email Addresses (attack-pattern)
- Upload Malware (attack-pattern)
- Bumblebee (malware)
- Bazar (malware)
Exploited vulnerabilities
- CVE-2021-40444 (vulnerability)
Reports & references
- Microsoft — Analyzing Attacks That Exploit The Mshtml Cve 2021 40444 Vulnerability (report)
- blog.google — Exposing Initial Access Broker Ties Conti (report)
- MITRE ATT&CK — G1011 (report)