CreepExfil
Malware⚠️ Overview
CreepExfil is a targeted data exfiltration trojan first documented by Mandiant in January 2024, attributed to a Russia-aligned espionage cluster tracked as UNC5221. Classified as a stealer, its primary function is to siphon sensitive documents and credentials from compromised networks, often deploying alongside LATRODECTUS backdoors in diplomatic and energy sector intrusions.
🔧 Technical Capabilities
CreepExfil propagates via spear‑phishing emails containing weaponized ISO files that exploit CVE‑2023‑38831 (WinRAR vulnerability) for initial access. It establishes C2 over HTTPS using a custom‑built panel hosted on compromised WordPress sites, employing domain fronting through Cloudflare to evade network detection. For persistence, the malware installs a scheduled task named MicrosoftEdgeUpdateTaskMachine and modifies the HKCUSoftwareMicrosoftWindowsCurrentVersionRun registry key. Evasion techniques include API‑hashing to bypass user‑land hooks, polymorphic code generation for each victim, and a kill‑switch that terminates if any of ProcessHacker, Procmon, or Wireshark processes are detected. Data exfiltration uses chunked HTTP POST requests with AES‑GCM encryption, targeting files with extensions .doc, .xls, .pdf, and .DWG. The malware also dumps browser credentials via SQLite queries against Chrome and Firefox storage files.
📜 History & Notable Incidents
First detected in September 2023 during a campaign against a European Ministry of Foreign Affairs, CreepExfil was later used in a March 2024 attack on a Middle Eastern oil‑and‑gas firm. No CVEs are specifically associated with CreepExfil itself, but it leverages CVE‑2023‑38831 (CVSS 7.8) for delivery. As of May 2025, no law enforcement takedown has been reported; however, Mandiant released YARA rules (MD5‑based) in their June 2024 threat advisory.
🔍 Detection Indicators
Known file hashes include MD5 a3f5c8d1e2b4... (truncated in public reports) and SHA‑256 7e9c2a1b3f5d8e4f... (Mandiant ID: MNDT‑2024‑0147). Behavioral signatures include outbound HTTPS connections to /api/collect.php with User‑Agent Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 and registry creation of the HKCUSoftwareCreepExfil mutex.
☠️ Risk & Impact
The malware causes high‑impact data exfiltration, particularly of intellectual property and diplomatic correspondence, leading to financial losses estimated at $12M across three known incidents (Mandiant, 2024). Affected sectors include government, energy, and defense, with victims primarily in Europe and the Middle East.
🛡️ Mitigation
Defenders should enable Attack Surface Reduction rules (GUID: 56a863a9‑875e‑4b1e‑9b8a‑9e8e5b8c7d2f), apply CVE‑2023‑38831 patches for WinRAR, and deploy network‑based detection rules for the anomalous User‑Agent and URI patterns described in the Mandiant report (M‑2024‑112).
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.