Lily Spider

Details

LILY SPIDER likely operates as a private access broker for other adversaries, most commonly Ransomware-as-a-Service (RaaS) operators. LILY SPIDER registers domains that mimic real companies and uses them as part of social-engineering campaigns against victims. LILY SPIDER poses as a potential customer to entice victims into opening malicious files sent from file-sharing services such ...

Community Identifiers

8jeCGLwd4UkzMlo

Objective

  • zxjlVDqeJZ9vgG6

Motivation

  • hSZrJi7w

Contact our team about
IOCs for this adversary

?

During a cybersecurity incident, indicators of compromise (IoC) are clues and evidence of a data breach.