POLONIUM, also tracked as Plaid Rain and previously by Microsoft as DEV-0133, is a Lebanon-based cyber-espionage threat actor assessed to coordinate with actors affiliated with Iran’s Ministry of Intelligence and Security (MOIS). The group was first publicly documented in 2022, but operations have been observed since at least September 2021. POLONIUM has focused primarily, and in reported activity almost exclusively, on organizations in Israel. The actor’s targeting has spanned government, defense, financial, information technology, engineering, communications, media, legal, insurance, manufacturing, marketing, and social-services organizations. Its operations are characterized by intelligence collection rather than destructive or financially motivated activity. POLONIUM is notable for maintaining a diverse custom malware ecosystem, including backdoors such as CreepyDrive, CreepySnail, DeepCreep, MegaCreep, FlipCreep, TechnoCreep, and PapaCreep, along with supporting modules for keylogging, screenshot capture, webcam surveillance, reverse shell access, tunneling, and file theft. The group has repeatedly abused legitimate cloud platforms including OneDrive, Dropbox, and Mega for command and control and exfiltration, helping its traffic blend with normal enterprise SaaS usage. Other observed command channels have included HTTP, FTP, and raw TCP sockets. Observed tradecraft includes suspected use of stolen credentials and vulnerability exploitation for initial access, persistence via Startup items and scheduled tasks, use of proxying and tunneling utilities, and exfiltration of stolen data to attacker-controlled cloud storage. POLONIUM has also used legitimate or dual-use tools such as Plink and VPN software in support of operations. The group’s malware is modular and has shown ongoing refinement, indicating sustained operational development and a mature espionage mission.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
36 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with the CreepyDrive OneDrive-based implant that uses Microsoft Graph API and OneDrive for command-and-control tasking and data exfiltration, blending malicious traffic with legitimate Office 365 activity.
Associated with the CreepyDrive OneDrive-based implant that uses the Microsoft Graph API against a user's OneDrive for command-and-control tasking and data exfiltration.
Listed as an associated threat actor in the detection annotation for a Linux usermod root UID set analytic; no specific campaign or activity is described in this reference.
Referenced as a threat actor associated with proxy-based command-and-control behavior relevant to abuse of tunneling/proxy mechanisms.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.