IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Google exposes 'uniquely personal' access broker behind worst Conti, FIN12 ransomware attacks

Investigation unveils the inner workings of one access broker that helped two of the most-hated ransomware gangs in history

The outline of a skull displayed in computer code to represent malware

Google’s cyber security research division has unearthed details of initial access brokers (IABs) working on behalf of some of the biggest ransomware gangs in existence.

IABs are groups of cyber criminals that exploit vulnerabilities in organisations and sell that access to the highest bidder so they can launch meaningful cyber attacks without conducting the initial leg work.

The Threat Analysis Group (TAG) observed the EXOTIC LILY IAB operating from at least as far back as September 2021 and has provided access to companies for the likes of Conti and FIN12 so they can launch profitable ransomware attacks.

These types of IAB groups have been operating for some time but have gained popularity in recent years and are approaching the peak of their operational maturity, according to recent reports.

FIN12 and the now-shuttered Conti are among the most infamous ransomware operators of recent times. They have both indiscriminately targeted organisations for financial gain and, unlike other groups, display few ethical boundaries, both having targeted hospitals and healthcare organisations in the past.

The well-resourced EXOTIC LILY group, at the peak of its activity, is said to have targeted upwards of 5,000 emails a day across 650 global organisations, attempting to exploit a Microsoft zero-day vulnerability (CVE-2021-40444) to achieve initial access.

Uniquely personal approach

Google’s TAG said EXOTIC LILY displayed targeted attack techniques such as spoofing companies and employees as a means to gaining trust through email campaigns but “rather uniquely” devoted a considerable amount of time to each target in an attempt to build trust.

Like the large-scale ransomware gangs it works for, EXOTIC LILY is comprised of many individuals so they can devote time to each target. TAG said the “level of human-interaction is rather unusual for cyber crime groups focused on mass-scale operations”.

TAG said EXOTIC LILY would customise business proposal templates when first contacting organisations rather than relying on just one, a technique requiring more effort than typically observed with such groups.

The IAB also handled additional communications with the victims in order to build trust sending a link to a malicious payload using legitimate file-sharing services.

The likes of WeTransfer, TransferNow, and OneDrive were used to deliver the payload that exploited the Microsoft zero-day, which was another technique the attackers used to evade detection mechanisms, TAG said.

EXOTIC LILY’s attack chain remained consistent throughout TAG’s analysis and can be broken down into just a few steps:

  1. Register [legitimate company name].us to imitate [legitimate company name].com
  2. Create “employee@[legitimate company name].us” email address
  3. Use OSINT or a website contact form to acquire target’s email address, send a phishing email
  4. Establish trust with further discussion or by scheduling a meeting
  5. Share payload with target
  6. Send a file-sharing notification
Model of the IAB's method of attack


The group first used fake online profiles with AI-generated faces to impersonate employees at a spoofed company, but later resorted to stealing genuine employees’ data and harvesting more from databases like CrunchBase and RocketReach.

Related Resource

How a platform approach to security monitoring initiatives adds value

Integration, orchestration, analytics, automation, and the need for speed

Whitepaper cover with title on burgundy square graphicFree Download

The use of a legitimate file-sharing service became a powerful method of avoiding detection, as not only are they familiar companies, but the target also receives a genuine file-sharing notification from that provider to increase the perceived authenticity.

EXOTIC LILY first used documents containing an exploit for a Microsoft zero-day but later changed strategy to delivering ISO files with hidden BazarLoader DLLs – a fileless attack method also common with ransomware groups.

Microsoft shortcut files, known as LNK shortcuts, were also delivered in these ISO files, with samples indicating they were custom-made by EXOTIC LILY rather than off-the-shelf exploit kits, TAG said.

Featured Resources

Activation playbook: Deliver data that powers impactful, game-changing campaigns

Bringing together data and technology to drive better business outcomes

Free Download

In unpredictable times, a data strategy is key

Data processes are crucial to guide decisions and drive business growth

Free Download

Achieving resiliency with Everything-as-a-Service (XAAS)

Transforming the enterprise IT landscape

Free Download

What is contextual analytics?

Creating more customer value in HR software applications

Free Download


Apple executive rejoins Google over remote work policy
flexible working

Apple executive rejoins Google over remote work policy

18 May 2022
Here’s the first look at Google’s new Bay View campus
Business operations

Here’s the first look at Google’s new Bay View campus

17 May 2022
Google offers UK SMBs £87,000 scholarships to boost tech skills
Careers & training

Google offers UK SMBs £87,000 scholarships to boost tech skills

10 May 2022
Google Cloud confirms it is building a dedicated team to support Web3 developers

Google Cloud confirms it is building a dedicated team to support Web3 developers

9 May 2022

Most Popular

Europe's first autonomous petrol station opens in Lisbon

Europe's first autonomous petrol station opens in Lisbon

23 May 2022
16 ways to speed up your laptop

16 ways to speed up your laptop

13 May 2022
Nvidia pauses hiring to help cope with inflation
Careers & training

Nvidia pauses hiring to help cope with inflation

23 May 2022