Threats Feed|Plaid Rain (Polonium)|Last Updated 24/07/2026|AuthorCertfa Radar|Publish Date11/10/2022

POLONIUM Cyber Espionage: Focused Attacks on Israeli Organizations Across Multiple Sectors

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Compromised Credentials,Backdoor,Keylogger,Malware
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

The POLONIUM group has been actively targeting more than a dozen organizations in Israel since September 2021, with a focus on various sectors including engineering, IT, law, communications, branding and marketing, media, insurance, and social services. The group's arsenal comprises several custom backdoors like CreepyDrive, CreepySnail, DeepCreep, MegaCreep, FlipCreep, TechnoCreep, and PapaCreep, along with other spying modules. These backdoors utilize cloud services like OneDrive, Dropbox, and Mega for command and control operations and are involved in collecting confidential data without engaging in sabotage or ransomware activities. The initial access to targeted systems might have been gained through the abuse of leaked VPN credentials.

Detected Targets

TypeDescriptionConfidence
SectorInformation Technology
Verified
SectorInsurance
Verified
SectorMedia
Verified
SectorTelecommunication
Verified
RegionIsrael
Verified

Extracted IOCs

  • 03a35a0167684e6ccca641296969972e49b88d60
  • 04378736da5c2da06bd5b15a41aaccac233df44b
  • 0832fec447b9b8a90ef4797c7b098b06e198d167
  • 0ce82be2f436d179b54a0cc6fcc675010822d268
  • 12ae1d7e2485dbb51aabbdb2b4cec6261cf43116
  • 1438f9fc50e914cb63b209a3312aa2857a410769
  • 1929900b68ac8a65d515002d313336781801e3ef
  • 21b4bf095e7c0eac92af96be1c2c6b0231807142
  • 21ef3d7adca478145c5d28fcf9c786c5f0aea0e6
  • 22d9058c3706e7a713949093f82d8bff4a8afa62
  • 235341ef26c356a302b7641f4097a87cc027d5c2
  • 23ce10c11dcd93bcbf2a4e50d4cd02dc862b9cc4
  • 23f1e9788688184712dc2b0eaad4c51584edabd0
  • 23f8f2e7558ed894e800cce9ea352c0d8efb2216
  • 24117276a118df5095d139aaaac8342f150de94a
  • 243e21af3c97ff2a6f705c05d0e62e97931d620e
  • 298c100aa98e79e54ca8454f8400e9543791fa15
  • 2b9444b0e1747eb4f482d29c9de27d07cce55a76
  • 3024f8b0439d7c271967d22373604215a4ce0ac4
  • 309f1750a63c3bcb8cad83a65a69a401f04c51d2
  • 3115939f4abf600bd0d17cb8aacca3c9cd786e64
  • 31c5dda0181daac130e900368b97adda8b09b762
  • 35c67f8b6f9d6b32a021edd7d59fafe868341c8a
  • 378dd134ff6cc55f36496ee717e4efca022bd754
  • 37a4a82075c24dbd3678c037f7abd2dbae49678f
  • 37e8036e20b93a4aed5b6bd600b97cbaf6964567
  • 3f4e3c5301752d39daf97384cca47564da1c3314
  • 43e3c3752a15d0bde7135e1b52f1de397b5314b5
  • 457c34aeaf4e2e5086221b20fec17df29a6b49d3
  • 459aece315af3d00342e5dde5fb79e7a908e8460
  • 45b3af39c5ef08f7407b94d564a432503b00275a
  • 45e56d259a7194c7c3adfefd8ada077dc2b800b8
  • 465c4351273ffad066b991bb4ec1956f34ee8082
  • 4a54c5dc45ce0047291dc98ad87f42cfe9fa046e
  • 4e7dbff20995e97190536b284d7e5cc65922fd55
  • 5036863519737b54c5d68891ee2e3ca795044803
  • 53bee089331b9bc06dd1ee3fe5e5b8bd3107ffdd
  • 550adbb75c7e1cd178cb8c39f0911c494b24c687
  • 5a0df60f25538883957d67675ae73a87d10cad91
  • 5c33a153f221f80c916b7e505f6e2144cd5b88a2
  • 5d8a4e53a96fd0c7809ba7d9cd6e730da00e1321
  • 5eef1ac7df2293d9432362fc586a7a7157b69157
  • 5f40f2da77ba7ef01f2ee4143d6022a0ef28c8f1
  • 5f7a338bb99aed422e1a69fe48726d42dbe71854
  • 62986c220efea9d64f4903461a8a6d2541ed6a7a
  • 67600c5b1b6221385c4b34dbbb80037dffcb171e
  • 691aa02384e5121598d21606445ab41325cdfa52
  • 6b5296db642689a5ad249cb66a5ae85ec664fd2c
  • 7722386c075db083878496875c156c67238758e6
  • 79de0af2f10f8d39a93eed911d4048d87e3c8a1c
  • 7a9deb71f791eb8d781250b0c8c3d546d91fbde1
  • 7cfa11879af6cea88cffa2aab354fb79bf77132a
  • 7d6550f8992515f79a43473bebdf2593caf25900
  • 806aeca473af9afef5a0ab29f30a9a272d9cec51
  • 809048a40274350bd0c453e49d8c1f7d32397164
  • 81606f1cdb7efcae54c66876fc3f31e84b8f7f15
  • 83a4f138d57fce4256727e517a8d19e67554c15f
  • 84e4aab5f5e2afbfa5b314d720e02e33c49d526d
  • 86377c1b8d54536c79c71f8913b72ca88d230bd4
  • 87684a3dcaa1488bf0579dc1e27304f6c64f794a
  • 89014d65d24dc14357a34d1d251e4cd43de6856d
  • 8aa46b8d0c47d447b87920a5a7494ce235707d7d
  • 8bb125624b52e3d2d82c272a0d1dd3906e1c3978
  • 8c0c39418339a0458809125de1a88a0c005694bd
  • 8e7818cc76da718c6d35d430e9d4763ecb940318
  • 911bc1e7c3d2295bb5ad01412c6fdcf2d937bd41
  • 92f3ae51657659098c0a0110b9a681d32b77e9c1
  • 93a625513ecba05c56f6ac45de3a5745edabfe2a
  • 94e75ba7c4476afdacf4b39e403379c5ecd1bed6
  • 97ed514f7510852c558a1b32c99f56ebc460dd8b
  • 9826aa25f2f005f9567f512f540cbed4d054692f
  • 994ead7666a67e33c57a51ef98076d41aabb7fb7
  • 99f7ef4d8eb9903543ce9c8201baa342d242b6ae
  • 9b03c838727fa3ada42bb4fa0422129ebfabf7bb
  • 9d7cf542cb3af7bf3e364ef01c73f3c74b0abae2
  • 9e25e2a18f1dc3a38c59a1408f982d895ce1b9b4
  • a02bcb0aa90004651c87873d9387dc6c00367643
  • a0a2768d500714f62b64b57185e71140d3c993d1
  • a19ba5d1ea315e0ca3a9a3ea6ccffc756404cec0
  • a22318388bbe3014d087e20f1a2bf363071ade0a
  • a4ac86b005c20d239cd0088d774ced701adc1d01
  • a9febe898daef40e7819a7b3bfef19462db894c5
  • aa442a83b7cd173734552b6611c50d050efe8277
  • ab9bf33a0cc0e676c4f843b1dc163861e6b13b6f
  • addafa922ef03e0fe25ab53cf8eb62f4c1cbdc02
  • b48cbb7a5f9bfbfbfb07113fb3728132d528e1f3
  • b601e9249d53b22e43c01f83d2356e9c7b41a443
  • b6371ef797c85f87128a696ec9c9edb93d90aae2
  • b7f0c0a26df905aed543658df3d752de363ab8a3
  • b810ed016e708f1c828dce82051c4b265794d583
  • b87cc5269a5df5cf093f8d28df78952f662162b6
  • bb39a928343d04a38addf122449d68fddf5f7e29
  • bf90d666626423741576072547c19b9ccd1459a7
  • c77cfd19d504da2639bf51e96ac27db3ff455d45
  • c7d4cf00bd2d90e03191657b89b75bfc9d2df5d8
  • cc820ed9a23084104807941b76a2679243ba357c
  • d0f05a5ad4e13610605b2d4b60854bfc002799c2
  • d5637caf5a931335b6b887a5ccbe36fffa6b4f9c
  • db3f13d29a64205780b9a675019405bb338ca375
  • e50765d980fd662f4e5c5609cb1876ab67815ef5
  • e889e5bbb128e38c0924a67c0946c699bd2de3b3
  • f074085be2a913c54100686fe7ef274a53323bda
  • f26f43ad2e2980b96497242a3f30ca003e5cf54c
  • f3b714698311bd6b7984f0dafa425f71f07c764c
  • f5505b35c9e9b6515875bea5c0bbf564add4939e
  • 146[.]70.86.6
  • 185[.]203.119.99
  • 185[.]244.129.216
  • 185[.]244.129.79
  • 195[.]166.100.23
  • 212[.]73.150.174
  • 37[.]120.233.89
  • 45[.]137.148.7
  • 45[.]80.148.119
  • 45[.]80.148.167
  • 45[.]80.148.186
  • 45[.]80.149.108
  • 45[.]80.149.154
  • 45[.]80.149.22
  • 45[.]80.149.68
  • 45[.]80.149.71
  • 51[.]83.246.73
  • 94[.]156.189.103
download

Tip: 123 related IOCs (18 IP, 0 domain, 0 URL, 0 email, 105 file hash) to this threat have been found.

Overlaps

PoloniumIranian-Linked POLONIUM Targets Israeli Manufacturing and Defense Industries

Source: Microsoft - June 2022

Detection (five cases): 185[.]244.129.79, 45[.]80.149.108, 45[.]80.149.68, 45[.]80.149.71, 51[.]83.246.73

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

POLONIUM Espionage Campaign

A highly active cyber threat group known as POLONIUM has been conducting targeted attacks using a vast arsenal of custom malware tools. They deployed various backdoors and modules to compromise systems, execute commands, and spy on victims.

The attack was carried out by POLONIUM, an active threat group known for exclusively building and constantly modifying its own custom tools. They are notable for dividing their malware into small components and heavily abusing popular cloud storage services.

The attacks are highly targeted and are focused on spying on victims. The attackers utilize specialized modules to log keystrokes, take screenshots, capture webcam photos, and exfiltrate files.

Public reports and intelligence about POLONIUM's activities are very scarce and limited. This lack of visibility is likely due to the highly targeted nature of their attacks rather than broad, widespread campaigns.

The report does not specify the targeted industries, but the group actively targets victims' data by capturing files, screenshots, and webcam snapshots. Notably, their custom keylogger supports both Hebrew and Arabic keyboards, suggesting regional targeting interests.

While the exact initial entry method is unconfirmed, attackers may have used leaked VPN credentials to breach networks. Once inside, they deployed custom backdoors that communicated with the attackers through popular cloud services (like Dropbox, OneDrive, and Mega) to stealthily receive commands and steal data.

While not explicitly stated, the highly targeted nature of the attacks implies the victims hold specific confidential data of value. Furthermore, the use of custom Hebrew and Arabic keyloggers indicates a strong interest in individuals or entities operating in those specific languages.

Organizations should secure their VPN accounts, ensuring that any credentials leaked in September 2021 are changed immediately. Defenders should also monitor their networks for unauthorized connections to cloud storage services and unusual execution patterns involving small files or built-in system tools.

This is a highly targeted issue. Intelligence on the group is limited precisely because they focus their attacks carefully rather than launching large, indiscriminate campaigns.

About Affiliation
Plaid Rain
Plaid Rain is Microsoft's current designation for the Iranian-linked threat actor previously known as Polonium, a Lebanon-based group first documented in 2022. The group targets Israeli organizations across critical manufacturing, IT, defense, transportation, government, healthcare, and financial sectors. Plaid Rain is assessed to coordinate with Iranian MOIS-linked actors, with victim overlap suggesting MOIS provides pre-established access to target networks. The group deploys custom cloud-based implants including CreepyDrive and CreepySnail, abusing OneDrive and other legitimate services for command and control. In at least one case, the group compromised an Israeli cloud service provider to conduct a supply chain attack. Microsoft renamed the group Plaid Rain in 2023.
View Plaid Rain's Insights