EXOTIC LILY
[EXOTIC LILY](https://attack.mitre.org/groups/G1011) is a financially motivated group that has been closely linked with [Wizard Spider](https://attack.mitre.org/groups/G0102) and the deployment of ransomware including [Conti](https://attack.mitre.org/software/S0575) and [Diavol](https://attack.mitre.org/software/S0659). [EXOTIC LILY](https://attack.mitre.org/groups/G1011) may be acting as an initial access broker for other malicious actors, and has targeted a wide range of industries including IT, cybersecurity, and healthcare since at least September 2021.(Citation: Google EXOTIC LILY March 2022)
Properties
- stix_id
- intrusion-set--129f2f77-1ab2-4c35-bd5e-21260cee92af
- signal_observed_at
- 2026-09-11T17:54:59+00:00
- type
- intrusion-set
MITRE ATT&CK Techniques (15)
Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresse
Adversaries may create email accounts that can be used during targeting. Adversaries can use accounts created with email providers to further their op
Adversaries may gather email addresses that can be used during targeting. Even if internal instances exist, organizations may have public-facing email
Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to ope
An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to cl
Adversaries may search and gather information about victims from closed (e.g., paid, private, or otherwise not freely available) sources that can be u
Adversaries may search websites owned by the victim for information that can be used during targeting. Victim-owned websites may contain a variety of
Adversaries may search social media for information about victims that can be used during targeting. Social media sites may contain various informatio
Adversaries may create and cultivate social media accounts that can be used during targeting. Adversaries can create social media accounts that can be
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a sp
Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specifi
Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a sp
Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting. Malicious software can in
Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud se
Software & Tools (3)
[Bazar](https://attack.mitre.org/software/S0534) is a downloader and backdoor that has been used since at least April 2020, with infections primarily
[Bumblebee](https://attack.mitre.org/software/S1039) is a custom loader written in C++ that has been used by multiple threat actors, including possibl
[Bumblebee](https://attack.mitre.org/software/S1039) is a custom loader written in C++ that has been used by multiple threat actors, including possibl
Explore this actor's full graph with Ninja Signal