Threats Feed|Plaid Rain (Polonium)|Last Updated 24/07/2026|AuthorCertfa Radar|Publish Date04/12/2023

Iranian-Backed Polonium Group Targets Israeli Critical Infrastructure

  • Actor Motivations: Espionage,Sabotage
  • Attack Vectors: Vulnerability Exploitation
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

The Polonium attack group, associated with the Lebanese faction and the Iranian Ministry of Intelligence, is actively targeting sectors in Israel, namely water, energy, and IT. This group's primary focus is on cyber espionage (CNE), with a recent shift towards potentially destructive activities (CNA). Their strategy involves exploiting known vulnerabilities (N-Day) and leveraging public VPN and cloud services, particularly PCloud, for communication and control. Despite these efforts, significant breaches in Israeli systems have not been confirmed. An alert highlights the risk of exploiting vulnerabilities in Fortinet equipment, underlining the need for enhanced cyber defense measures in the targeted sectors.

Detected Targets

TypeDescriptionConfidence
SectorInformation Technology
Verified
SectorEnergy
Verified
RegionIsrael
Verified

Extracted IOCs

  • 185[.]225.70.169
download

Tip: 1 related IOCs (1 IP, 0 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.

FAQs

Polonium Cyber Threat

A cyber attack system known as Polonium has been operating against organizations in Israel. The attackers are exploiting known software weaknesses to carry out their operations, though they have not achieved significant success so far.

The Polonium attack system is operated by a Lebanese group. This group conducts its operations in cooperation with the Iranian Ministry of Intelligence.

The main purpose of the group is to gather information. Recently, a new trend has been identified where the group attempts to carry out destructive attacks.

The cyber operations are specifically targeted against organizations located in Israel.

Yes, the attackers are specifically targeting organizations operating in the water, energy, and IT sectors.

The attackers gain initial access by exploiting known vulnerabilities in equipment, such as Fortinet devices. Once they gain a foothold, they maintain persistence and use public VPNs and cloud services, like PCloud, to command their attack tools.

The targeted entities belong to critical infrastructure areas like the water, energy, and IT sectors in Israel. Compromising these sectors serves the group's overarching purpose of gathering information and carrying out destructive attacks.

Organizations should take care of all relevant organizational protection systems. They must also pay close attention to warnings regarding the exploitation of vulnerabilities in Fortinet equipment.

This is a highly targeted issue aimed specifically at certain organizational sectors within Israel.

About Affiliation
Plaid Rain
Plaid Rain is Microsoft's current designation for the Iranian-linked threat actor previously known as Polonium, a Lebanon-based group first documented in 2022. The group targets Israeli organizations across critical manufacturing, IT, defense, transportation, government, healthcare, and financial sectors. Plaid Rain is assessed to coordinate with Iranian MOIS-linked actors, with victim overlap suggesting MOIS provides pre-established access to target networks. The group deploys custom cloud-based implants including CreepyDrive and CreepySnail, abusing OneDrive and other legitimate services for command and control. In at least one case, the group compromised an Israeli cloud service provider to conduct a supply chain attack. Microsoft renamed the group Plaid Rain in 2023.
View Plaid Rain's Insights