ATT&CKReferencesGoogle EXOTIC LILY March 2022

Google EXOTIC LILY March 2022

Stolyarov, V. (2022, March 17). Exposing initial access broker with ties to Conti. Retrieved August 18, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareBumblebee

Bumblebee has the ability to identify the user name.

T1041
Exfiltration Over C2 Channel
MalwareBumblebee

Bumblebee can send collected data in JSON format to C2.

T1047
Windows Management Instrumentation
MalwareBumblebee

Bumblebee can use WMI to gather system information and to spawn processes for code injection.

T1059.003
Windows Command Shell
MalwareBumblebee

Bumblebee can use `cmd.exe` to drop and run files.

T1082
System Information Discovery
MalwareBumblebee

Bumblebee can enumerate the OS version and domain on a targeted system.

T1102
Web Service
GroupEXOTIC LILY

EXOTIC LILY has used file-sharing services including WeTransfer, TransferNow, and OneDrive to deliver payloads.

T1105
Ingress Tool Transfer
MalwareBumblebee

Bumblebee can download and execute additional payloads including through the use of a `Dex` command.

T1203
Exploitation for Client Execution
GroupEXOTIC LILY

EXOTIC LILY has used malicious documents containing exploits for CVE-2021-40444 affecting Microsoft MSHTML.

T1204.001
Malicious Link
GroupEXOTIC LILY

EXOTIC LILY has used malicious links to lure users into executing malicious payloads.

T1204.002
Malicious File
GroupEXOTIC LILY

EXOTIC LILY has gained execution through victims clicking on malicious LNK files contained within ISO files, which can execute hidden DLLs within the ISO.

T1566.001
Spearphishing Attachment
GroupEXOTIC LILY

EXOTIC LILY conducted an e-mail thread-hijacking campaign with malicious ISO attachments.

T1566.002
Spearphishing Link
GroupEXOTIC LILY

EXOTIC LILY has relied on victims to open malicious links in e-mails for execution.

T1566.003
Spearphishing via Service
GroupEXOTIC LILY

EXOTIC LILY has used the e-mail notification features of legitimate file sharing services for spearphishing.

T1583.001
Domains
GroupEXOTIC LILY

EXOTIC LILY has registered domains to spoof targeted organizations by changing the top-level domain (TLD) to “.us”, “.co” or “.biz”.

T1585.001
Social Media Accounts
GroupEXOTIC LILY

EXOTIC LILY has established social media profiles to mimic employees of targeted companies.

T1585.002
Email Accounts
GroupEXOTIC LILY

EXOTIC LILY has created e-mail accounts to spoof targeted organizations.

T1589.002
Email Addresses
GroupEXOTIC LILY

EXOTIC LILY has gathered targeted individuals' e-mail addresses through open source research and website contact forms.

T1593.001
Social Media
GroupEXOTIC LILY

EXOTIC LILY has copied data from social media sites to impersonate targeted individuals.

T1594
Search Victim-Owned Websites
GroupEXOTIC LILY

EXOTIC LILY has used contact forms on victim websites to generate phishing e-mails.

T1597
Search Closed Sources
GroupEXOTIC LILY

EXOTIC LILY has searched for information on targeted individuals on business databases including RocketReach and CrunchBase.

T1608.001
Upload Malware
GroupEXOTIC LILY

EXOTIC LILY has uploaded malicious payloads to file-sharing services including TransferNow, TransferXL, WeTransfer, and OneDrive.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.