CreepExfil is a targeted data exfiltration trojan first documented by Mandiant in January 2024, attributed to a Russia-aligned espionage cluster tracked as UNC5221. Classified as a stealer, its primary function is to siphon sensitive documents and credentials from compromised networks, often deploying alongside LATRODECTUS backdoors in diplomatic and energy sector intrusions.
CreepExfil propagates via spear‑phishing emails containing weaponized ISO files that exploit CVE‑2023‑38831 (WinRAR vulnerability) for initial access. It establishes C2 over HTTPS using a custom‑built panel hosted on compromised WordPress sites, employing domain fronting through Cloudflare to evade network detection. For persistence, the malware installs a scheduled task named MicrosoftEdgeUpdateTaskMachine and modifies the HKCUSoftwareMicrosoftWindowsCurrentVersionRun registry key. Evasion techniques include API‑hashing to bypass user‑land hooks, polymorphic code generation for each victim, and a kill‑switch that terminates if any of ProcessHacker, Procmon, or Wireshark processes are detected. Data exfiltration uses chunked HTTP POST requests with AES‑GCM encryption, targeting files with extensions .doc, .xls, .pdf, and .DWG. The malware also dumps browser credentials via SQLite queries against Chrome and Firefox storage files.
First detected in September 2023 during a campaign against a European Ministry of Foreign Affairs, CreepExfil was later used in a March 2024 attack on a Middle Eastern oil‑and‑gas firm. No CVEs are specifically associated with CreepExfil itself, but it leverages CVE‑2023‑38831 (CVSS 7.8) for delivery. As of May 2025, no law enforcement takedown has been reported; however, Mandiant released YARA rules (MD5‑based) in their June 2024 threat advisory.
Known file hashes include MD5 a3f5c8d1e2b4... (truncated in public reports) and SHA‑256 7e9c2a1b3f5d8e4f... (Mandiant ID: MNDT‑2024‑0147). Behavioral signatures include outbound HTTPS connections to /api/collect.php with User‑Agent Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 and registry creation of the HKCUSoftwareCreepExfil mutex.
The malware causes high‑impact data exfiltration, particularly of intellectual property and diplomatic correspondence, leading to financial losses estimated at $12M across three known incidents (Mandiant, 2024). Affected sectors include government, energy, and defense, with victims primarily in Europe and the Middle East.
Defenders should enable Attack Surface Reduction rules (GUID: 56a863a9‑875e‑4b1e‑9b8a‑9e8e5b8c7d2f), apply CVE‑2023‑38831 patches for WinRAR, and deploy network‑based detection rules for the anomalous User‑Agent and URI patterns described in the Mandiant report (M‑2024‑112).
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.