Actors Insights|Latest update24/07/2026

Plaid Rain

Named by MicrosoftSuspected state sponsor: Islamic Republic of Iran

Plaid Rain is Microsoft's current designation for the Iranian-linked threat actor previously known as Polonium, a Lebanon-based group first documented in 2022. The group targets Israeli organizations across critical manufacturing, IT, defense, transportation, government, healthcare, and financial sectors. Plaid Rain is assessed to coordinate with Iranian MOIS-linked actors, with victim overlap suggesting MOIS provides pre-established access to target networks. The group deploys custom cloud-based implants including CreepyDrive and CreepySnail, abusing OneDrive and other legitimate services for command and control. In at least one case, the group compromised an Israeli cloud service provider to conduct a supply chain attack. Microsoft renamed the group Plaid Rain in 2023.

This threat actor previously was known as Polonium
First Seen:Mar 2022
Last Seen:Dec 2023
Indexed Reports:3
Public IOCs:128
Cluster: UnclassifiedMitre: POLONIUMMisp: POLONIUM
also known as:
Plaid Rain (Microsoft)UNC4453GREATRIFTINCENDIARY JACKALPOLONIUM (Microsoft)G1005 (Mitre)

Targeted Regions

Israel
IL
Israel
Israel
Mar 2022 ~ Jun 2022
Mar 2022 ~ Jun 2022
Sep 2022 ~ Oct 2022
Nov 2023 ~ Dec 2023
Nov 2023 ~ Dec 2023
Lebanon
LB
Lebanon
Lebanon
Mar 2022 ~ Jun 2022
Mar 2022 ~ Jun 2022
Jan 2022Nov 2026

Targeted Sectors

Information TechnologyInsuranceMediaTelecommunicationEnergyDefenseFinancialFood and AgricultureGovernment Agencies and ServicesManufacturingAerospaceHealthcareTransportation

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.