Also known as: Plaid Rain, UNC4453, GREATRIFT, INCENDIARY JACKAL
POLONIUM is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at least February 2022. Security researchers assess POLONIUM has coordinated their operations with multiple actors affiliated with Iran’s Ministry of Intelligence and Security (MOIS), based on victim overlap as well as common techniques and tooling.(Citation: Microsoft POLONIUM June 2022)
Targeted Sectors
Executive Summary
POLONIUM, also known as Plaid Rain, UNC4453, GREATRIFT, and INCENDIARY JACKAL, is a Lebanon-based threat actor suspected to have ties with Iran’s Ministry of Intelligence and Security (MOIS). Primarily active since February 2022, POLONIUM has targeted Israeli organizations across multiple sectors, including manufacturing, defense, IT, and healthcare. Their operations suggest a coordinated approach, likely state-sponsored, using sophisticated tactics and tools.
Goals & Targeting
POLONIUM targets sectors vital to national security and economic interests with possible espionage or disruptive goals. Their focus on Israel suggests a political or strategic agenda aligned with Iran. Likely objectives include data theft, supply chain compromise, or undermining critical infrastructure.
Enhanced Description
POLONIUM is a Lebanon-based threat group identified by Microsoft in June 2022 as coordinating with Iranian-affiliated actors, targeting Israeli sectors like manufacturing, IT, defense, healthcare, financial services, government, pharmaceuticals, transportation, and non-profits. Operations since February 2022 involve compromised relationships and cloud storage exfiltration.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
POLONIUM is linked to long-term campaigns, leveraging trusted relationships and cloud services. Their operations are likely part of broader nation-state strategies targeting Israel and related sectors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence based on Microsoft's analysis and known TTPs. Limited data on exact campaigns or additional tools may exist.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
7
Techniques
2
Tools
0
Campaigns
0
IOCs
0
Observed Data
5
Tactics