Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors EXOTIC LILY

Also known as: DEV-0413

Description

EXOTIC LILY is a financially motivated group that has been closely linked with Wizard Spider and the deployment of ransomware including Conti and Diavol. EXOTIC LILY may be acting as an initial access broker for other malicious actors, and has targeted a wide range of industries including IT, cybersecurity, and healthcare since at least September 2021.(Citation: Google EXOTIC LILY March 2022)

AI Analysis

· 2 months ago

Executive Summary

EXOTIC LILY, also known as DEV-0413, is a financially motivated threat actor closely linked with Wizard Spider, known for deploying ransomware such as Conti and Diavol. The group has been active since at least September 2021, targeting various industries including IT, cybersecurity, and healthcare. EXOTIC LILY's activities suggest they may be acting as an initial access broker for other malicious actors.

Goals & Targeting

EXOTIC LILY's strategic objectives are centered around gaining initial access to target networks and exploiting them for financial gain. The group targets a wide range of industries, including IT, cybersecurity, and healthcare, in pursuit of lucrative paydays. Their typical victims are organizations with valuable data or systems that can be compromised for ransom, highlighting the importance of robust cybersecurity measures to prevent such attacks.

Enhanced Description

The close links between EXOTIC LILY and Wizard Spider highlight the complex and interconnected nature of the cyber threat landscape. EXOTIC LILY's potential role as an initial access broker for other malicious actors adds another layer of complexity, as it suggests that they may be facilitating the activities of other threat groups. This underscores the need for organizations to remain vigilant and proactive in their cybersecurity posture, as the threat landscape continues to evolve and become more sophisticated.

Key Capabilities

  • Initial access brokering
  • Ransomware deployment
  • Network exploitation
  • Data exfiltration
  • Lateral movement

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1204
T1547.001

Software / Tooling

Conti ransomware
Diavol ransomware
Custom malware

Campaigns & Victims

EXOTIC LILY's campaign patterns are characterized by their opportunistic and adaptable nature, with the group pursuing a wide range of industries and organizations. Their operational tempo is likely to be high, with multiple concurrent campaigns and operations. Notable past operations include the deployment of Conti and Diavol ransomware, highlighting the group's focus on financial gain. The group's activities have been observed since at least September 2021, with a potential increase in activity in recent months.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting

Recommended Actions

  • Implement robust email security controls to prevent spear-phishing
  • Conduct regular network vulnerability assessments
  • Enforce strong password policies and multi-factor authentication
  • Monitor for suspicious DNS activity
  • Implement a robust incident response plan

Suggested Tags

APT
Ransomware
Financially motivated
Initial access broker

Confidence Assessment

The confidence level in the available data is moderate, with some gaps in information regarding EXOTIC LILY's exact motivations and capabilities. Further research and analysis are needed to fully understand the scope and nature of the threat posed by this group. The available data suggests a high degree of sophistication and adaptability, but more information is required to confirm the group's exact TTPs and to identify potential vulnerabilities that can be exploited for defensive purposes.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Google EXOTIC LILY March 2022 — Stolyarov, V. (2022, March 17). Exposing initial access broker with ties to Conti. Retrieved August 18, 2022.

Intel Summary

15

Techniques

2

Tools

0

Campaigns

0

IOCs

0

Observed Data

5

Tactics

Tags

Ransomware
Healthcare Targeting

Details

MITRE ID
G1011
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--129f2f77-1ab2-4c35-bd5e-21260cee92af
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.