CreepyDrive is a malware component in the Creepy malware toolset associated with the Plaid Rain threat cluster, a Lebanon-based actor first documented in 2022 that primarily targets Israeli entities in the defense, government, manufacturing, and financial sectors. Reporting cited in the content notes potential coordination between Plaid Rain and Iran-nexus actors affiliated with Iran’s Ministry of Intelligence and Security. CreepyDrive uses legitimate cloud services, specifically Microsoft OneDrive, for command-and-control and for data exfiltration, likely to make malicious traffic appear legitimate and evade detection. It can upload files from victim machines to its C2 infrastructure. The malware can also use PowerShell for execution, including the cmdlets Invoke-WebRequest and Invoke-Expression. High-confidence behaviors directly mentioned in the content are OneDrive-based C2, OneDrive-based exfiltration, file upload from victim hosts, and PowerShell-based execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For example, the CreepyDrive malware uses Cloud services for command and control purposes, likely in an attempt to evade detection by making malicious traffic look legitimate.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."
Several entries describe broader use of HTTP/HTTPS and related web mechanisms for C2, including "Crutch has conducted C2 communications with a Dropbox account using the HTTP API," "BLUELIGHT can use HTTP/S for C2 using the Microsoft Graph API," and "Small Sieve can contact actor-controlled C2 servers by using the Telegram API over HTTPS."
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
"APT39 has communicated with C2 through files uploaded to and downloaded from DropBox."; "RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results ... back to Google Drive."; "CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data"
Many entries state malware or actors can upload, transfer, send, or exfiltrate files from compromised hosts to command-and-control servers or attacker infrastructure.
Akira will exfiltrate victim data using applications such as Rclone. APT41 DUST exfiltrated collected information to OneDrive. BoomBox can upload data to dedicated per-victim folders in Dropbox. During C0015, the threat actors exfiltrated files and sensitive data to the MEGA cloud storage site using the Rclone command.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Part of Plaid Rain's Creepy malware toolset; uses cloud services for command and control to blend malicious traffic with legitimate activity.
Malware that leverages cloud services such as OneDrive for data exfiltration.
Backdoor that uses PowerShell cmdlets such as Invoke-WebRequest and Invoke-Expression for execution.
Backdoor that can use Microsoft OneDrive for command-and-control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.