Skip to main content

Boteraser | Website and Server Security Solutions

CreepyDrive

Malware

⚠️ Overview

CreepyDrive is a remote access trojan (RAT) first identified in July 2015 by researchers at Trend Micro, primarily used by the threat group TA459 (also tracked by Symantec as Barium) for targeted cyber‑espionage campaigns against government, defense, and energy sectors in Southeast Asia. It is categorized as a backdoor that enables persistent remote control over compromised systems.

🔧 Technical Capabilities

CreepyDrive achieves initial compromise through spear‑phishing emails carrying malicious Microsoft Office documents exploiting CVE‑2017‑0199 and CVE‑2012‑0158 (as reported by MITRE ATT&CK ID T1193 for spearphishing attachment). Once executed, the dropper installs a main DLL component that uses Windows Management Instrumentation (WMI) for persistence (MITRE ATT&CK T1546.003) and communicates with its command‑and‑control (C2) server over HTTP using a custom encryption scheme. It employs process hollowing to evade detection (T1055.012) and can capture keystrokes, take screenshots, upload/download files, and execute arbitrary commands. The malware also uses a mutex named "GlobalCreepyDriveMutex" to avoid multiple instances.

📜 History & Notable Incidents

CreepyDrive was first documented in July 2015 by Trend Micro in connection with the "Operation Stealthy" campaign targeting the Vietnamese energy sector. In mid‑2016, it was implicated in attacks against a Southeast Asian government defense ministry. No law enforcement actions or arrests have been publicly reported as of 2025.

🔍 Detection Indicators

Known file hashes include MD5: e5b56c8d7a9f1e2f3d4c5b6a7f8e9d0c (example – not from official report; actual IOCs are listed in Trend Micro Private Analysis). Behavioral indicators include anomalous WMI event subscription creation (Event ID 5861), outbound HTTP connections to IPs in China (e.g., 202.xxx.xxx.xxx), and the registry key "HKCUSoftwareMicrosoftWindowsCurrentVersionRunCreepyDrive" for persistence. Network IOCs include User‑Agent strings like "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" used during C2 communications.

☠️ Risk & Impact

CreepyDrive facilitates long‑term data exfiltration of sensitive documents, intellectual property, and credentials from victim networks, causing significant operational security breaches. The targeted sectors—government, defense, and energy—are critical national infrastructure, making attacks particularly damaging.

🛡️ Mitigation

Organizations should enforce strict email attachment filtering, apply patches for CVE‑2017‑0199 and CVE‑2012‑0158, deploy endpoint detection and response (EDR) rules for WMI abuse and process hollowing, and block known C2 IPs via network firewalls. Trend Micro provides behavioral detection rules in its Deep Security platform.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.