ATT&CKSoftwareCreepySnail

CreepySnail

S1024

Malware.View on attack.mitre.org

About this malware

CreepySnail is a custom PowerShell implant that has been used by POLONIUM since at least 2022.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1016
System Network Configuration Discovery

CreepySnail can use `getmac` and `Get-NetIPAddress` to enumerate network settings.

T1033
System Owner/User Discovery

CreepySnail can execute `getUsername` on compromised systems.

T1041
Exfiltration Over C2 Channel

CreepySnail can connect to C2 for data exfiltration.

T1059.001
PowerShell

CreepySnail can use PowerShell for execution, including the cmdlets `Invoke-WebRequst` and `Invoke-Expression`.

T1071.001
Web Protocols

CreepySnail can use HTTP for C2.

T1078.002
Domain Accounts

CreepySnail can use stolen credentials to authenticate on target networks.

T1132.001
Standard Encoding

CreepySnail can use Base64 to encode its C2 traffic.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Microsoft POLONIUM June 2022 Open source
    Microsoft. (2022, June 2). Exposing POLONIUM activity and infrastructure targeting Israeli organizations. Retrieved July 1, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.