CreepyDrive — Malware Profile
CreepyDrive is a custom implant has been used by POLONIUM since at least early 2022 for C2 with and exfiltration to actor-controlled OneDrive accounts. POLONIUM has used a similar implant called CreepyBox that relies on actor-controlled DropBox accounts.
MITRE ATT&CK techniques (8)
- T1005 Data from Local System
- T1059.001 PowerShell
- T1071.001 Web Protocols
- T1083 File and Directory Discovery
- T1102.002 Bidirectional Communication
- T1105 Ingress Tool Transfer
- T1550.001 Application Access Token
- T1567.002 Exfiltration to Cloud Storage