ATT&CKSoftwareCreepyDrive

CreepyDrive

S1023

Malware.View on attack.mitre.org

About this malware

CreepyDrive is a custom implant has been used by POLONIUM since at least early 2022 for C2 with and exfiltration to actor-controlled OneDrive accounts.

POLONIUM has used a similar implant called CreepyBox that relies on actor-controlled DropBox accounts.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1005
Data from Local System

CreepyDrive can upload files to C2 from victim machines.

T1059.001
PowerShell

CreepyDrive can use Powershell for execution, including the cmdlets `Invoke-WebRequest` and `Invoke-Expression`.

T1071.001
Web Protocols

CreepyDrive can use HTTPS for C2 using the Microsoft Graph API.

T1083
File and Directory Discovery

CreepyDrive can specify the local file path to upload files from.

T1102.002
Bidirectional Communication

CreepyDrive can use OneDrive for C2.

T1105
Ingress Tool Transfer

CreepyDrive can download files to the compromised host.

T1550.001
Application Access Token

CreepyDrive can use legitimate OAuth refresh tokens to authenticate with OneDrive.

T1567.002
Exfiltration to Cloud Storage

CreepyDrive can use cloud services including OneDrive for data exfiltration.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Microsoft POLONIUM June 2022 Open source
    Microsoft. (2022, June 2). Exposing POLONIUM activity and infrastructure targeting Israeli organizations. Retrieved July 1, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.