Plaid Rain
Named by MicrosoftSuspected state sponsor: Islamic Republic of IranPlaid Rain is Microsoft's current designation for the Iranian-linked threat actor previously known as Polonium, a Lebanon-based group first documented in 2022. The group targets Israeli organizations across critical manufacturing, IT, defense, transportation, government, healthcare, and financial sectors. Plaid Rain is assessed to coordinate with Iranian MOIS-linked actors, with victim overlap suggesting MOIS provides pre-established access to target networks. The group deploys custom cloud-based implants including CreepyDrive and CreepySnail, abusing OneDrive and other legitimate services for command and control. In at least one case, the group compromised an Israeli cloud service provider to conduct a supply chain attack. Microsoft renamed the group Plaid Rain in 2023.
Targeted Regions
IsraelIsrael
Mar 2022 ~ Jun 2022
Mar 2022 ~ Jun 2022
Sep 2022 ~ Oct 2022
Nov 2023 ~ Dec 2023
Nov 2023 ~ Dec 2023
LebanonLebanon
Mar 2022 ~ Jun 2022
Mar 2022 ~ Jun 2022
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.