Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors POLONIUM

Also known as: Plaid Rain, UNC4453, GREATRIFT, INCENDIARY JACKAL

Description

POLONIUM is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at least February 2022. Security researchers assess POLONIUM has coordinated their operations with multiple actors affiliated with Iran’s Ministry of Intelligence and Security (MOIS), based on victim overlap as well as common techniques and tooling.(Citation: Microsoft POLONIUM June 2022)

Goals & Targeting

Targeted Sectors

Manufacturing
Defense
Financial services
Government
Healthcare
Pharmaceutical
Information technology
Transportation
Non profit

AI Analysis

· 1 week ago

Executive Summary

POLONIUM, also known as Plaid Rain, UNC4453, GREATRIFT, and INCENDIARY JACKAL, is a Lebanon-based threat actor suspected to have ties with Iran’s Ministry of Intelligence and Security (MOIS). Primarily active since February 2022, POLONIUM has targeted Israeli organizations across multiple sectors, including manufacturing, defense, IT, and healthcare. Their operations suggest a coordinated approach, likely state-sponsored, using sophisticated tactics and tools.

Goals & Targeting

POLONIUM targets sectors vital to national security and economic interests with possible espionage or disruptive goals. Their focus on Israel suggests a political or strategic agenda aligned with Iran. Likely objectives include data theft, supply chain compromise, or undermining critical infrastructure.

Enhanced Description

POLONIUM is a Lebanon-based threat group identified by Microsoft in June 2022 as coordinating with Iranian-affiliated actors, targeting Israeli sectors like manufacturing, IT, defense, healthcare, financial services, government, pharmaceuticals, transportation, and non-profits. Operations since February 2022 involve compromised relationships and cloud storage exfiltration.

Key Capabilities

  • Compromised actor relationships
  • Cloud storage exfiltration
  • Proxy communication channels
  • Spear-phishing via malicious links/injects
  • Tailored malware

MITRE ATT&CK Tactics

Information Gathering
Supply Chain Compromise
Tooling
Exfiltration
Defense Evasion
Valid Accounts
Communication

ATT&CK Techniques

T1583.006
T1199
T1588.002
T1567.002
T1090
T1078
T1102.002

Software / Tooling

CreepyDrive
CreepySnail

Campaigns & Victims

POLONIUM is linked to long-term campaigns, leveraging trusted relationships and cloud services. Their operations are likely part of broader nation-state strategies targeting Israel and related sectors.

IOC Patterns

  • Phishing emails with malicious links/attachments
  • Exfiltration via cloud storage
  • C2 communication using compromised infrastructure

Recommended Actions

  • Monitor cloud storage for unauthorized access
  • Enhance MaaS provider vetting
  • Implement network monitoring for suspicious activities
  • Strengthen account security protocols
  • Educate users on phishing threats

Suggested Tags

APT
espionage
nation-state
cyber espionage

Confidence Assessment

High confidence based on Microsoft's analysis and known TTPs. Limited data on exact campaigns or additional tools may exist.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  2. Microsoft POLONIUM June 2022 — Microsoft. (2022, June 2). Exposing POLONIUM activity and infrastructure targeting Israeli organizations. Retrieved July 1, 2022.

Intel Summary

7

Techniques

2

Tools

0

Campaigns

0

IOCs

0

Observed Data

5

Tactics

Tags

Government Targeting
APT
espionage
nation-state
cyber espionage

Details

MITRE ID
G1005
Type
Unknown
Country of Origin
L
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--5f3d0238-d058-44a9-8812-3dd1b6741a8c
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.