CreepySnail is a custom PowerShell backdoor used by POLONIUM in cyberespionage operations targeting Israeli organizations. It operates on Windows systems, communicates with attacker-controlled command-and-control servers over HTTP, and receives and executes PowerShell commands. It uses Invoke-WebRequest for web communications and Invoke-Expression for command execution, and can Base64-encode its command-and-control traffic.
The backdoor supports discovery of the current user's name and data exfiltration through its command-and-control channel. It can also authenticate to target networks using stolen credentials, supporting access within compromised environments; this does not establish that it independently steals credentials. CreepySnail belongs to POLONIUM's broader custom backdoor arsenal. The Lebanon-based group's targeting has included engineering, information technology, legal services, communications, media, insurance, and social services organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
POLONIUM has all the hallmarks of an APT: sophistication, political motives (read: 2006 Lebanon War), data exfiltration, and the use of custom malware including the PowerShell implant “CreepySnail”.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
“attempted to acquire valid credentials for victim environments… to enable follow-on lateral movement… leverages valid accounts… used legitimate account credentials to move laterally… used compromised domain admin account to move laterally… used domain administrators' accounts to help facilitate lateral movement…”
“attempted to acquire valid credentials for victim environments… to enable follow-on lateral movement… leverages valid accounts… used legitimate account credentials to move laterally… used compromised domain admin account to move laterally… used domain administrators' accounts to help facilitate lateral movement…”
“attempted to acquire valid credentials for victim environments… to enable follow-on lateral movement… leverages valid accounts… used legitimate account credentials to move laterally… used compromised domain admin account to move laterally… used domain administrators' accounts to help facilitate lateral movement…”
“attempted to acquire valid credentials for victim environments… to enable follow-on lateral movement… leverages valid accounts… used legitimate account credentials to move laterally… used compromised domain admin account to move laterally… used domain administrators' accounts to help facilitate lateral movement…”
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
CreepySnail and POLONIUM’s file exfiltrator modules use HTTP communication with the C&C server.
C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding... APT19 HTTP malware variant used Base64 to encode communications to the C2 server... APT33 has used base64 to encode command and control traffic.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that can execute getUsername on compromised systems.
A PowerShell backdoor that communicates with a C2 server over HTTP to receive and execute PowerShell commands, with multiple minimally different versions observed.
Custom PowerShell implant used by POLONIUM. The article places it within the group's campaigns targeting Israeli organizations but does not describe its specific capabilities.
Backdoor that uses PowerShell for execution, including web request and expression invocation cmdlets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.