POLONIUM
Also known as: Plaid Rain
Overview
POLONIUM is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at least February 2022. Security researchers assess POLONIUM has coordinated their operations with multiple actors affiliated with Iran’s Ministry of Intelligence and Security (MOIS), based on victim overlap as well as common techniques and tooling.
Naming & attribution
POLONIUM is tracked under 2 names across the industry. It uses 7 documented ATT&CK techniques — more than 20% of the 174 groups tracked here.
| Name | First reported by |
|---|---|
| Plaid Rain | Microsoft |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Carbanak — 3 shared techniques (23% overlap)
- Cinnamon Tempest China — 4 shared techniques (18% overlap)
- Sea Turtle — 3 shared techniques (10% overlap)
- Earth Lusca China — 4 shared techniques (9% overlap)
- LAPSUS$ — 4 shared techniques (9% overlap)
- ZIRCONIUM China — 3 shared techniques (9% overlap)
Targets
Civil society · Critical Manufacturing · Defense · Defense industrial base · Financial Services · Food And Agriculture · Government Agencies And Services · Healthcare · Military · NGOs · Pharmaceuticals · Technology · Transportation
Regions
Israel
TTPs — 7 techniques across 5 tactics
Resource Development
-
T1583.006Web Services -
T1588.002Tool
Initial Access
-
T1199Trusted Relationship
Stealth
-
T1078Valid Accounts
Command and Control
-
T1090Proxy -
T1102.002Bidirectional Communication
Exfiltration
-
T1567.002Exfiltration to Cloud Storage
Tools & malware (2)
CreepyDrive · CreepySnail