logo

Email Threats: Exotic Lily

ID: fed0e82a-a9c0-58ff-95f7-acec6291cd92

STIX ID: report--fed0e82a-a9c0-58ff-95f7-acec6291cd92

Feed Name: ReliaQuest Blog

Threat Score
75/100

Date Published: 2023-03-08

Date Updated: 2026-04-29

...
...

ReliaQuest Photon investigated targeted phishing by the Initial Access Broker 'Exotic Lily' (aka PROJECTOR LIBRA/TA580) that leverages high-fidelity impersonation, TLD spoofing, and legitimate filesharing platforms to deliver ZIP archives containing ISO/IMG images with LNK shortcuts; these shortcuts have deployed loaders (BumbleBee or a Python-based loader) which in one case loaded a Cobalt Strike beacon before the host was contained. The report details the group's methodology, a recent incident, and recommends heightened user awareness and automated phishing analysis (GreyMatter Phishing Analyzer) to accelerate detection and containment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.