Google’s Threat Analysis Group uncovers Initial Access Broker group that serves both the Conti and Diavol ransomware groups. Initial access brokers are locksmiths of the security world. They specialize in breaching a target to open the doors – or the Windows – to the malicious actor with the highest bid. The group would create entirely fake personas posing as employees of a real company. At the peak of Exotic Lily’s activity, we estimate they were sending more than 5,000 emails a day, to as many as 650 targeted organizations.”]
Source: https://www.cuinfosecurity.com/google-exposes-initial-access-broker-ties-to-ransomware-a-18758

