Also known as: DEV-0413
EXOTIC LILY is a financially motivated group that has been closely linked with Wizard Spider and the deployment of ransomware including Conti and Diavol. EXOTIC LILY may be acting as an initial access broker for other malicious actors, and has targeted a wide range of industries including IT, cybersecurity, and healthcare since at least September 2021.(Citation: Google EXOTIC LILY March 2022)
Executive Summary
EXOTIC LILY, also known as DEV-0413, is a financially motivated threat actor closely linked with Wizard Spider, known for deploying ransomware such as Conti and Diavol. The group has been active since at least September 2021, targeting various industries including IT, cybersecurity, and healthcare. EXOTIC LILY's activities suggest they may be acting as an initial access broker for other malicious actors.
Goals & Targeting
EXOTIC LILY's strategic objectives are centered around gaining initial access to target networks and exploiting them for financial gain. The group targets a wide range of industries, including IT, cybersecurity, and healthcare, in pursuit of lucrative paydays. Their typical victims are organizations with valuable data or systems that can be compromised for ransom, highlighting the importance of robust cybersecurity measures to prevent such attacks.
Enhanced Description
The close links between EXOTIC LILY and Wizard Spider highlight the complex and interconnected nature of the cyber threat landscape. EXOTIC LILY's potential role as an initial access broker for other malicious actors adds another layer of complexity, as it suggests that they may be facilitating the activities of other threat groups. This underscores the need for organizations to remain vigilant and proactive in their cybersecurity posture, as the threat landscape continues to evolve and become more sophisticated.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
EXOTIC LILY's campaign patterns are characterized by their opportunistic and adaptable nature, with the group pursuing a wide range of industries and organizations. Their operational tempo is likely to be high, with multiple concurrent campaigns and operations. Notable past operations include the deployment of Conti and Diavol ransomware, highlighting the group's focus on financial gain. The group's activities have been observed since at least September 2021, with a potential increase in activity in recent months.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data is moderate, with some gaps in information regarding EXOTIC LILY's exact motivations and capabilities. Further research and analysis are needed to fully understand the scope and nature of the threat posed by this group. The available data suggests a high degree of sophistication and adaptability, but more information is required to confirm the group's exact TTPs and to identify potential vulnerabilities that can be exploited for defensive purposes.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
15
Techniques
2
Tools
0
Campaigns
0
IOCs
0
Observed Data
5
Tactics