CreepyDrive
S1023 · Windows, Office Suite
CreepyDrive is a custom implant has been used by POLONIUM since at least early 2022 for C2 with and exfiltration to actor-controlled OneDrive accounts. POLONIUM has used a similar implant called CreepyBox that relies on actor-controlled DropBox accounts.
ATT&CK S1023
Sigma rules0
YARA rules0
Live IOCs0