Intrusion setG1011
EXOTIC LILY
EXOTIC LILY is a financially motivated group that has been closely linked with Wizard Spider and the deployment of ransomware including Conti and Diavol. EXOTIC LILY may be acting as an initial access broker for other malicious actors, and has targeted a wide range of industries including IT, cybersecurity, and healthcare since at least September 2021.
- Documented techniques
- 15
- Assessed motivation
- Financial gain
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
reconnaissance4
resource development4
initial access3
command and control1
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
BazarBumblebee