Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware CreepyDrive

CreepyDrive

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

CreepyDrive is a cloud‑based implant used by POLONIUM, employing actor‑controlled OneDrive accounts for C2 communication and data exfiltration. It targets Windows machines running Microsoft Office, leveraging legitimate cloud APIs to evade traditional detection mechanisms. Immediate defensive action is required to monitor for unusual OneDrive activity and block known malicious content.

Enhanced Description

CreepyDrive is a custom Windows and Microsoft Office implant that has been attributed to the state‑backed group POLONIUM since at least early 2022. The malware establishes command‑and‑control (C&C) connections through actor‑controlled OneDrive accounts, exploiting the web‑service interface of Microsoft’s cloud storage platform to send instructions and receive exfiltrated data back to the attackers. Once installed on a victim machine, CreepyDrive can execute arbitrary payloads received via OneDrive, thereby providing POLONIUM with a persistent foothold that is both geographically distributed and difficult for traditional network perimeter defenses to block. The implant also leverages Office application integrations (such as malicious macros or embedded objects) to facilitate initial infection and lateral movement within an environment. POLONIUM’s use of similar implants—most notably CreepyBox, which relies on Dropbox accounts—is evidence of a broader cloud‑centric strategy that shifts C&C traffic from hardened servers to consumer cloud services. By using legitimate cloud storage for both command delivery and data exfiltration, the actors reduce their operational footprint while evading many conventional IDS/IPS rules. While detailed technical documentation on installation procedures, persistence mechanisms, or in‑memory operations remains sparse, security researchers have confirmed that CreepyDrive can compromise Office files and use OneDrive’s API for both inbound commands and outbound data. The limited field reports suggest that the attackers target Windows workstations with active Office installations in order to maximize exposure to the exploit vector.

Key Capabilities

  • Establishes command‑and‑control via actor‑controlled OneDrive accounts
  • Exfiltrates stolen data to cloud storage using the OneDrive API
  • Injects malicious payloads into Microsoft Office documents
  • Attempts persistence on Windows systems (possible service or scheduled task creation)

ATT&CK Techniques

T1071.001
T1041
T1105

Recommended Actions

  • Monitor outbound traffic for unusual Graph API calls and OneDrive file uploads
  • Block or quarantine newly created files under corporate OneDrive folders that lack user approval
  • Implement endpoint detection that alerts on execution of Office macros from unknown sources
  • Deploy network segmentation to isolate workstations from direct Internet access where feasible
  • Enforce strict application whitelisting and real‑time script scanning

Suggested Tags

POLONIUM
CreepyDrive
OneDrive
Cloud C&C
Microsoft Office Exploit
APT

Confidence Assessment

The available data offers high confidence in the attribution of CreepyDrive to POLONIUM and its use of OneDrive for C2 and exfiltration. However, gaps remain regarding precise infection vectors, persistence techniques, memory‑resident behavior, and full payload capabilities, limiting a complete picture of the malware’s operational complexity.

Description

CreepyDrive is a custom implant has been used by POLONIUM since at least early 2022 for C2 with and exfiltration to actor-controlled OneDrive accounts.(Citation: Microsoft POLONIUM June 2022) POLONIUM has used a similar implant called CreepyBox that relies on actor-controlled DropBox accounts.(Citation: Microsoft POLONIUM June 2022)

Details

Type
Malware
Platforms
Windows
Office suite
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.