LILY SPIDER likely operates as a private access broker for other adversaries, most commonly Ransomware-as-a-Service (RaaS) operators. LILY SPIDER registers domains that mimic real companies and uses them as part of social-engineering campaigns against victims. LILY SPIDER poses as a potential customer to entice victims into opening malicious files sent from file-sharing services such ...
Contact our team about
IOCs for this adversary