NEW: Group Profiler — instant APT intel lookup. Try it →

POLONIUM

G1005 Espionage MITRE ATT&CK →

Also known as: Plaid Rain

Overview

POLONIUM is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at least February 2022. Security researchers assess POLONIUM has coordinated their operations with multiple actors affiliated with Iran’s Ministry of Intelligence and Security (MOIS), based on victim overlap as well as common techniques and tooling.

Naming & attribution

POLONIUM is tracked under 2 names across the industry. It uses 7 documented ATT&CK techniques — more than 20% of the 174 groups tracked here.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Plaid RainMicrosoft

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Carbanak — 3 shared techniques (23% overlap)
  • Cinnamon Tempest China — 4 shared techniques (18% overlap)
  • Sea Turtle — 3 shared techniques (10% overlap)
  • Earth Lusca China — 4 shared techniques (9% overlap)
  • LAPSUS$ — 4 shared techniques (9% overlap)
  • ZIRCONIUM China — 3 shared techniques (9% overlap)

Targets

Civil society · Critical Manufacturing · Defense · Defense industrial base · Financial Services · Food And Agriculture · Government Agencies And Services · Healthcare · Military · NGOs · Pharmaceuticals · Technology · Transportation

Regions

Israel

TTPs — 7 techniques across 5 tactics

Resource Development

Initial Access

Stealth

Command and Control

Exfiltration

Tools & malware (2)

CreepyDrive · CreepySnail

Reporting (2)