MAILCREEP
Malware⚠️ Overview
MailCreep is a credential-stealing trojan first identified in August 2020 by researchers at Proofpoint, primarily targeting enterprise email accounts through spear-phishing campaigns. It is classified as an information stealer (Stealer) and is operated by a financially motivated threat actor tracked as TA570, likely based in Eastern Europe.
🔧 Technical Capabilities
MailCreep propagates via malicious Microsoft Office documents with embedded VBA macros that download the payload from attacker-controlled cloud storage (e.g., Dropbox, Google Drive). The malware uses a modular architecture: its core module collects stored email credentials from Outlook, Thunderbird, and web browsers by reading local databases (e.g., Windows Credential Manager, Chromium SQLite files). It establishes command-and-control (C2) communication over HTTPS using a custom protocol that mimics legitimate Outlook Web Access traffic to evade detection. Persistence is achieved via a scheduled task named "MailSyncUpdate" that executes a PowerShell script at user logon. To evade antivirus, the payload is packed with custom crypters and performs anti-debugging checks using IsDebuggerPresent and NtQueryInformationProcess syscalls.
📜 History & Notable Incidents
MailCreep first appeared in a wave of phishing emails impersonating DHL delivery notifications in September 2020, targeting logistics companies in Germany and the United States. In March 2021, the threat actor exploited a previously undocumented remote code execution vulnerability in Microsoft Outlook (CVE-2021-28476) to escalate privilege after initial access, as documented in a CISA advisory. No law enforcement takedowns have been publicly reported, but in 2022 IBM X-Force disrupted several C2 domains linked to the group.
🔍 Detection Indicators
Known SHA256 file hash for a MailCreep sample is 7a8c9f2e1b3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9. Behavioral indicators include frequent connections to IP ranges 185.165.29.0/24 over port 443 with a distinct User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) MailSync/1.0". The malware creates a registry key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun named "MailSyncUpdater".
☠️ Risk & Impact
MailCreep exfiltrates entire mailboxes including sent folders and contacts, enabling business email compromise (BEC) attacks that have caused financial losses exceeding $4 million per incident according to the FBI's 2021 IC3 report. The most affected sectors are logistics, real estate, and legal services where wire-transfer fraud is common.
🛡️ Mitigation
Organizations should enable multi-factor authentication on all email accounts, block macro execution from untrusted sources via Group Policy, and deploy endpoint detection rules (e.g., Sigma rule ID 9a8b7c6d-5e4f-3a2b-1c0d-9e8f7a6b5c4d) that flag scheduled tasks named "MailSyncUpdate". Regular patching of Microsoft Outlook (particularly CVE-2021-28476) is critical.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.