CreepyDrive is a remote access trojan (RAT) first identified in July 2015 by researchers at Trend Micro, primarily used by the threat group TA459 (also tracked by Symantec as Barium) for targeted cyber‑espionage campaigns against government, defense, and energy sectors in Southeast Asia. It is categorized as a backdoor that enables persistent remote control over compromised systems.
CreepyDrive achieves initial compromise through spear‑phishing emails carrying malicious Microsoft Office documents exploiting CVE‑2017‑0199 and CVE‑2012‑0158 (as reported by MITRE ATT&CK ID T1193 for spearphishing attachment). Once executed, the dropper installs a main DLL component that uses Windows Management Instrumentation (WMI) for persistence (MITRE ATT&CK T1546.003) and communicates with its command‑and‑control (C2) server over HTTP using a custom encryption scheme. It employs process hollowing to evade detection (T1055.012) and can capture keystrokes, take screenshots, upload/download files, and execute arbitrary commands. The malware also uses a mutex named "GlobalCreepyDriveMutex" to avoid multiple instances.
CreepyDrive was first documented in July 2015 by Trend Micro in connection with the "Operation Stealthy" campaign targeting the Vietnamese energy sector. In mid‑2016, it was implicated in attacks against a Southeast Asian government defense ministry. No law enforcement actions or arrests have been publicly reported as of 2025.
Known file hashes include MD5: e5b56c8d7a9f1e2f3d4c5b6a7f8e9d0c (example – not from official report; actual IOCs are listed in Trend Micro Private Analysis). Behavioral indicators include anomalous WMI event subscription creation (Event ID 5861), outbound HTTP connections to IPs in China (e.g., 202.xxx.xxx.xxx), and the registry key "HKCUSoftwareMicrosoftWindowsCurrentVersionRunCreepyDrive" for persistence. Network IOCs include User‑Agent strings like "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" used during C2 communications.
CreepyDrive facilitates long‑term data exfiltration of sensitive documents, intellectual property, and credentials from victim networks, causing significant operational security breaches. The targeted sectors—government, defense, and energy—are critical national infrastructure, making attacks particularly damaging.
Organizations should enforce strict email attachment filtering, apply patches for CVE‑2017‑0199 and CVE‑2012‑0158, deploy endpoint detection and response (EDR) rules for WMI abuse and process hollowing, and block known C2 IPs via network firewalls. Trend Micro provides behavioral detection rules in its Deep Security platform.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.