Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: Plaid Rain
7
techniques
2
software
2,748
corpus matches
profile
POLONIUM is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at least February 2022. Security researchers assess POLONIUM has coordinated their operations with multiple actors affiliated with Iran’s Ministry of Intelligence and Security (MOIS), based on victim overlap as well as common techniques and tooling.
techniques
7 attributed · most-instrumented first
software
2 malware & tools attributed
CreepyDrive
S1023
CreepySnail
S1024
read this carefully
2,748 corpus matches is not attribution
That count is indicators which exhibit techniques POLONIUM is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
command-and-control
showing 30 of 2,748
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.