Polonium
Named by MicrosoftSuspected state sponsor: Islamic Republic of IranPolonium is a Lebanon-based threat actor first documented by Microsoft in June 2022, when it disabled the group's OneDrive command and control infrastructure. Active since at least February 2022, Polonium targeted over 20 Israeli organizations across critical manufacturing, IT, defense industrial base, transportation, government, healthcare, and financial sectors. Microsoft assessed with moderate confidence that Polonium coordinates its operations with actors affiliated with Iran's Ministry of Intelligence and Security (MOIS), based on victim overlap with MuddyWater-compromised networks — suggesting MOIS may provide Polonium with access to previously compromised environments as part of a hand-off operational model. The group abuses legitimate cloud services for command and control, deploying custom implants including CreepyDrive (OneDrive-based) and CreepySnail (PowerShell-based), and used Dropbox in later campaigns. In at least one case, Polonium compromised an Israeli cloud service provider to conduct a supply chain attack against a downstream aviation company and law firm. Microsoft renamed the group Plaid Rain in 2023.
Targeted Regions
IsraelIsrael
Sep 2021 ~ Oct 2022
Sep 2021 ~ Oct 2022
Sep 2021 ~ Oct 2022 Mar 2022 ~ Jun 2022
Sep 2021 ~ Oct 2022 Mar 2022 ~ Jun 2022
Sep 2021 ~ Oct 2022
Sep 2021 ~ Oct 2022
Nov 2023 ~ Dec 2023
LebanonLebanon
Mar 2022 ~ Jun 2022
Mar 2022 ~ Jun 2022
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.