CreepySnail — Malware Profile
CreepySnail is a custom PowerShell implant that has been used by POLONIUM since at least 2022.
MITRE ATT&CK techniques (7)
- T1016 System Network Configuration Discovery
- T1033 System Owner/User Discovery
- T1041 Exfiltration Over C2 Channel
- T1059.001 PowerShell
- T1071.001 Web Protocols
- T1078.002 Domain Accounts
- T1132.001 Standard Encoding