Malware.View on attack.mitre.org
CreepySnail is a custom PowerShell implant that has been used by POLONIUM since at least 2022.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
CreepySnail can use `getmac` and `Get-NetIPAddress` to enumerate network settings. |
| T1033 System Owner/User Discovery |
CreepySnail can execute `getUsername` on compromised systems. |
| T1041 Exfiltration Over C2 Channel |
CreepySnail can connect to C2 for data exfiltration. |
| T1059.001 PowerShell |
CreepySnail can use PowerShell for execution, including the cmdlets `Invoke-WebRequst` and `Invoke-Expression`. |
| T1071.001 Web Protocols |
CreepySnail can use HTTP for C2. |
| T1078.002 Domain Accounts |
CreepySnail can use stolen credentials to authenticate on target networks. |
| T1132.001 Standard Encoding |
CreepySnail can use Base64 to encode its C2 traffic. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.