CreepyDrive — Malware Profile

CreepyDrive is a custom implant has been used by POLONIUM since at least early 2022 for C2 with and exfiltration to actor-controlled OneDrive accounts. POLONIUM has used a similar implant called CreepyBox that relies on actor-controlled DropBox accounts.

MITRE ATT&CK techniques (8)

Attributed threat actors

Read the full analysis on IntelFusions