← threatfilter.dev / all groups / POLONIUM
POLONIUM
Also known as: Plaid Rain
Overview
POLONIUM is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at least February 2022. Security researchers assess POLONIUM has coordinated their operations with multiple actors affiliated with Iran’s Ministry of Intelligence and Security (MOIS), based on victim overlap as well as common techniques and tooling.
Targets
Civil society · Critical Manufacturing · Defense · Defense industrial base · Financial Services · Food And Agriculture · Government Agencies And Services · Healthcare · Military · NGOs · Pharmaceuticals · Technology · Transportation
Regions
Israel
TTPs — 7 techniques across 5 tactics
Resource Development
-
T1583.006Web Services -
T1588.002Tool
Initial Access
-
T1199Trusted Relationship
Stealth
-
T1078Valid Accounts
Command and Control
-
T1090Proxy -
T1102.002Bidirectional Communication
Exfiltration
-
T1567.002Exfiltration to Cloud Storage
Tools & malware (2)
CreepyDrive · CreepySnail