Malware.View on attack.mitre.org
CreepyDrive is a custom implant has been used by POLONIUM since at least early 2022 for C2 with and exfiltration to actor-controlled OneDrive accounts.
POLONIUM has used a similar implant called CreepyBox that relies on actor-controlled DropBox accounts.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
CreepyDrive can upload files to C2 from victim machines. |
| T1059.001 PowerShell |
CreepyDrive can use Powershell for execution, including the cmdlets `Invoke-WebRequest` and `Invoke-Expression`. |
| T1071.001 Web Protocols |
CreepyDrive can use HTTPS for C2 using the Microsoft Graph API. |
| T1083 File and Directory Discovery |
CreepyDrive can specify the local file path to upload files from. |
| T1102.002 Bidirectional Communication |
CreepyDrive can use OneDrive for C2. |
| T1105 Ingress Tool Transfer |
CreepyDrive can download files to the compromised host. |
| T1550.001 Application Access Token |
CreepyDrive can use legitimate OAuth refresh tokens to authenticate with OneDrive. |
| T1567.002 Exfiltration to Cloud Storage |
CreepyDrive can use cloud services including OneDrive for data exfiltration. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.