Exotic Lily is a financially motivated cybercrime threat actor and initial access broker known for conducting highly tailored phishing and impersonation operations to obtain footholds in victim environments and facilitate follow-on ransomware activity. The group has been publicly linked to access operations associated with Conti and has been reported to work with ransomware-affiliated actors including FIN12 and Wizard Spider. Exotic Lily is widely tracked under the name Exotic Lily, with aliases including exoticlily and exotic_lily. The actor specializes in social-engineering-driven initial access. Its tradecraft includes registering spoofed infrastructure that imitates targeted organizations, creating fraudulent email accounts and social media personas, and collecting victim information from open sources, business databases, social media, and website contact forms to improve targeting. Exotic Lily has conducted email thread hijacking and other impersonation-based phishing campaigns to increase credibility and response rates. Exotic Lily has delivered payloads through malicious links, spearphishing attachments, and abuse of legitimate file-sharing and cloud-sharing services. Reported delivery platforms include common transfer and storage services used to blend malicious traffic with normal business activity. The group has also used malicious documents exploiting CVE-2021-40444 in Microsoft MSHTML. A notable execution chain associated with Exotic Lily relies on ISO images containing malicious LNK files that trigger execution of hidden DLL payloads when opened by the victim. This reflects the group’s adaptation to changing defensive controls around macro-based delivery and its use of user-execution techniques centered on archive, disk image, and shortcut-file lures. Exotic Lily is best characterized as an access-focused cybercriminal actor rather than a nation-state intrusion set. Its operations emphasize reconnaissance, impersonation, phishing, and malware staging to compromise enterprise targets and broker or enable downstream ransomware intrusion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
EXOTIC LILY has used malicious documents containing exploits for CVE-2021-40444 affecting Microsoft MSHTML.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
31 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Initial access broker distributing malicious LNK files to infect systems for downstream ransomware activity.
Listed as a threat actor associated with the malicious file execution technique detected by this analytic.
Listed in the detection annotations as a threat actor associated with EFI volume mounting / installation-related behavior.
Listed as a threat actor associated with exploitation of public-facing applications and malware/tool upload activity relevant to Confluence exploitation detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.