CreepyDrive is a custom PowerShell backdoor associated with the POLONIUM activity cluster, a cyberespionage actor assessed as Lebanon-based and linked to coordination with actors affiliated with Iran’s MOIS. The implant is designed to abuse trusted cloud services for covert command-and-control and data theft, primarily using Microsoft OneDrive through the Microsoft Graph API, with some reporting also noting Dropbox-based tasking. By reading and writing tasking and response data through a victim-accessible cloud storage account over HTTPS, CreepyDrive blends malicious traffic with normal Office 365 and OneDrive activity and complicates network-based detection.
The malware supports bidirectional command-and-control, execution of PowerShell code, file upload from compromised hosts, file download to victim systems, and exfiltration of collected data to cloud storage. Reported tradecraft includes use of PowerShell cmdlets for web retrieval and execution, as well as abuse of legitimate OAuth refresh tokens to authenticate to OneDrive. This combination of trusted SaaS infrastructure, legitimate API usage, and valid authentication material provides both operational flexibility and defense evasion benefits.
CreepyDrive has been used in intrusions targeting organizations in Israel across sectors including engineering, information technology, law, communications, media, insurance, and social services. It fits POLONIUM’s broader pattern of modular espionage tooling focused on intelligence collection rather than disruptive or destructive effects. Within that ecosystem, CreepyDrive serves as a cloud-backed implant for persistent remote access, command execution, file transfer, and exfiltration on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
POLONIUM’s toolset consists of seven custom backdoors: CreepyDrive, which abuses OneDrive and Dropbox cloud services for C&C.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Bug 2: URL encoding The rule matches literal / and : characters. Percent-encoding those (%2F, %3A) means the raw logged string no longer matches...
CreepyDrive, is a OneDrive-based implant associated with the POLONIUM activity cluster. It reads and writes C2 tasking and exfil through the Microsoft Graph API against a normal user’s OneDrive, so from the network’s perspective it looks like Office 365. | It reads and writes C2 tasking and exfil through the Microsoft Graph API against a normal user’s OneDrive, so from the network’s perspective it looks like Office 365.
CreepySnail and POLONIUM’s file exfiltrator modules use HTTP communication with the C&C server.
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
It reads and writes C2 tasking and exfil through the Microsoft Graph API against a normal user’s OneDrive...
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A OneDrive-based implant that uses the Microsoft Graph API for command-and-control, reading tasking and writing responses/exfiltration data via OneDrive so its traffic blends in with normal Office 365 activity.
A OneDrive-based implant that uses the Microsoft Graph API for command-and-control, reading tasking and writing responses/exfiltration data through a victim or operator-controlled OneDrive account to blend with legitimate Office 365 traffic.
Part of Plaid Rain's Creepy malware toolset; uses cloud services for command and control to blend malicious traffic with legitimate activity.
A PowerShell backdoor that reads and executes commands from text files stored on OneDrive or Dropbox, and can upload/download files and execute supplied PowerShell code.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.