United StatesWidely attributedUnknownMITRE G1011

EXOTIC LILY

EXOTIC LILY is a financially motivated group that has been closely linked with Wizard Spider and the deployment of ransomware including Conti and Diavol. EXOTIC LILY may be acting as an initial access broker for other malicious actors, and has targeted a wide range of industries including IT, cybersecurity, and healthcare since at least September 2021.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
0.0
None signal strength
Mentions0
Sources0
High conf.0
First observed
2022-08-18
Last active
Origin
United States (cybercriminal)
Aliases
1
Techniques
15
Campaigns
0
United States (cybercriminal)

Attribution signals

No attribution signals extracted yet — signals populate automatically as articles are processed.