Executive Summary
CreepyDrive is a cloud‑based implant used by POLONIUM, employing actor‑controlled OneDrive accounts for C2 communication and data exfiltration. It targets Windows machines running Microsoft Office, leveraging legitimate cloud APIs to evade traditional detection mechanisms. Immediate defensive action is required to monitor for unusual OneDrive activity and block known malicious content.
Enhanced Description
CreepyDrive is a custom Windows and Microsoft Office implant that has been attributed to the state‑backed group POLONIUM since at least early 2022. The malware establishes command‑and‑control (C&C) connections through actor‑controlled OneDrive accounts, exploiting the web‑service interface of Microsoft’s cloud storage platform to send instructions and receive exfiltrated data back to the attackers. Once installed on a victim machine, CreepyDrive can execute arbitrary payloads received via OneDrive, thereby providing POLONIUM with a persistent foothold that is both geographically distributed and difficult for traditional network perimeter defenses to block. The implant also leverages Office application integrations (such as malicious macros or embedded objects) to facilitate initial infection and lateral movement within an environment. POLONIUM’s use of similar implants—most notably CreepyBox, which relies on Dropbox accounts—is evidence of a broader cloud‑centric strategy that shifts C&C traffic from hardened servers to consumer cloud services. By using legitimate cloud storage for both command delivery and data exfiltration, the actors reduce their operational footprint while evading many conventional IDS/IPS rules. While detailed technical documentation on installation procedures, persistence mechanisms, or in‑memory operations remains sparse, security researchers have confirmed that CreepyDrive can compromise Office files and use OneDrive’s API for both inbound commands and outbound data. The limited field reports suggest that the attackers target Windows workstations with active Office installations in order to maximize exposure to the exploit vector.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The available data offers high confidence in the attribution of CreepyDrive to POLONIUM and its use of OneDrive for C2 and exfiltration. However, gaps remain regarding precise infection vectors, persistence techniques, memory‑resident behavior, and full payload capabilities, limiting a complete picture of the malware’s operational complexity.
CreepyDrive is a custom implant has been used by POLONIUM since at least early 2022 for C2 with and exfiltration to actor-controlled OneDrive accounts.(Citation: Microsoft POLONIUM June 2022) POLONIUM has used a similar implant called CreepyBox that relies on actor-controlled DropBox accounts.(Citation: Microsoft POLONIUM June 2022)