Cyber-espionage group POLONIUM ran a sustained campaign against Israeli organizations, deploying a growing set of custom backdoors collectively dubbed Creepy malware. Researchers said the activity targeted more than a dozen victims across engineering, IT, law, communications, media, insurance, and social services, with operations observed from at least September 2021 through September 2022. The malware families included CreepyDrive, CreepySnail, DeepCreep, MegaCreep, FlipCreep, TechnoCreep, and PapaCreep, giving operators capabilities such as keylogging, screenshots, webcam capture, reverse shells, command execution, tunneling, and file exfiltration.
The campaign relied heavily on legitimate cloud platforms including Dropbox, OneDrive, and Mega for command-and-control and data theft, while other variants used TCP- or FTP-based communications. ESET described a modular toolset with persistence through Startup items and scheduled tasks, and Microsoft previously assessed POLONIUM as a Lebanon-based group coordinating with actors tied to Iran’s Ministry of Intelligence and Security. Initial access remains unconfirmed, but known VPN weaknesses and leaked Fortinet VPN credentials from some victims may have helped the attackers enter internal networks. Researchers said the operation was focused on intelligence collection rather than ransomware, wiper attacks, or other destructive activity.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
ESET listed 37.120.233[.]89 as a PapaCreep command-and-control server first seen on September 12, 2022. The server was associated with the newly observed modular backdoor.
ESET observed PapaCreep, a modular C++ backdoor, in September 2022. It was described as the first POLONIUM backdoor written in C++ and separates command execution, communications, upload, and download into components.
Microsoft Threat Intelligence first publicly documented POLONIUM's malicious activity in June 2022. Microsoft linked the group to Lebanon-based actors with ties to Iran's Ministry of Intelligence and Security.
ESET listed FlipCreep infrastructure at 45.137.148[.]7:2121 as first seen on October 29, 2021. FlipCreep is a C# backdoor that reads commands from an attacker-operated FTP server.
ESET listed TechnoCreep command-and-control and exfiltration infrastructure at 45.80.149[.]154 on ports 1302 and 21 as first seen on September 23, 2021. TechnoCreep is a C# backdoor that communicates over raw TCP sockets.
ESET noted that some victims' Fortinet VPN credentials were leaked online in September 2021, making credential abuse a possible route into internal networks. The initial compromise vector was not confirmed.
ESET telemetry indicates POLONIUM targeted more than a dozen organizations in Israel starting in September 2021. The campaign affected sectors including engineering, IT, law, communications, media, insurance, and social services.
ESET disclosed previously undocumented POLONIUM malware families and reported the campaign remained active through September 2022. The report detailed at least seven custom backdoors, including newly documented TechnoCreep, FlipCreep, MegaCreep, and PapaCreep, and described the group's abuse of Dropbox, OneDrive, and Mega for command-and-control.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 31 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.