CreepySnail is a custom PowerShell backdoor associated with the POLONIUM cyberespionage group. It has been used in operations targeting organizations in Israel across sectors including engineering, information technology, legal services, communications, media, insurance, and social services. POLONIUM has been publicly linked to long-running intelligence collection activity and assessed by Microsoft as coordinating with actors affiliated with Iran’s MOIS, while also being described as Lebanon-based.
CreepySnail communicates with command-and-control infrastructure over HTTP, receives PowerShell commands, and executes them on compromised systems. Observed behavior includes use of PowerShell execution primitives such as web-request retrieval and expression-based execution, collection of local username information, Base64 encoding of command-and-control traffic, and exfiltration of data through its command channel. It has also been documented using stolen credentials to authenticate on target networks, indicating utility beyond simple remote access and supporting follow-on intrusion activity.
Within POLONIUM’s broader toolset, CreepySnail formed part of a modular espionage ecosystem that included multiple custom backdoors and supporting components for surveillance and data theft. The malware is best characterized as an espionage-oriented PowerShell backdoor focused on remote command execution, victim profiling, credential-enabled access, and covert data collection from Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CreepySnail is another PowerShell backdoor that sends HTTP requests to a C&C server and receives and executes PowerShell commands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
“attempted to acquire valid credentials for victim environments… to enable follow-on lateral movement… leverages valid accounts… used legitimate account credentials to move laterally… used compromised domain admin account to move laterally… used domain administrators' accounts to help facilitate lateral movement…”
“attempted to acquire valid credentials for victim environments… to enable follow-on lateral movement… leverages valid accounts… used legitimate account credentials to move laterally… used compromised domain admin account to move laterally… used domain administrators' accounts to help facilitate lateral movement…”
“attempted to acquire valid credentials for victim environments… to enable follow-on lateral movement… leverages valid accounts… used legitimate account credentials to move laterally… used compromised domain admin account to move laterally… used domain administrators' accounts to help facilitate lateral movement…”
“attempted to acquire valid credentials for victim environments… to enable follow-on lateral movement… leverages valid accounts… used legitimate account credentials to move laterally… used compromised domain admin account to move laterally… used domain administrators' accounts to help facilitate lateral movement…”
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
CreepySnail and POLONIUM’s file exfiltrator modules use HTTP communication with the C&C server.
C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding... APT19 HTTP malware variant used Base64 to encode communications to the C2 server... APT33 has used base64 to encode command and control traffic.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that can execute getUsername on compromised systems.
A PowerShell backdoor that communicates with a C2 server over HTTP to receive and execute PowerShell commands, with multiple minimally different versions observed.
Backdoor that uses PowerShell for execution, including web request and expression invocation cmdlets.
Malware that can Base64-encode command-and-control traffic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.