POLONIUM, also known as Plaid Rain and Incendiary Jackal, is a Lebanon-based cyberespionage group active since at least September 2021 and publicly documented in June 2022. It primarily targets Israeli organizations across engineering, manufacturing, information technology, communications, media, legal services, insurance, social services, government, and defense. Its victim set also includes an intergovernmental organization operating in Lebanon. Microsoft assesses that the group coordinates with actors affiliated with Iran’s Ministry of Intelligence and Security; a direct Iranian command relationship has not been established. POLONIUM develops and maintains custom backdoors, including CreepyDrive, CreepySnail, DeepCreep, MegaCreep, FlipCreep, TechnoCreep, and PapaCreep, implemented in PowerShell, C#, and C++. These tools support remote command execution, payload installation, file transfers, and intelligence collection. Supporting modules provide keylogging, clipboard collection, screenshots, webcam capture, reverse shells, and tunneling. Its modular PapaCreep backdoor separates command execution, communications, uploads, and downloads into independently operating components. Persistence mechanisms include Startup items and scheduled tasks. A characteristic of POLONIUM’s operations is the abuse of legitimate cloud services, including OneDrive, Dropbox, and Mega, for command and control and data exfiltration. It also uses HTTP, raw TCP, and FTP communications, alongside AirVPN, Plink, and other proxying tools to conceal infrastructure and support remote access. The group has conducted at least one supply-chain intrusion through a compromised Israeli information technology company. Initial access mechanisms remain incompletely established. Its documented operations emphasize confidential-data collection rather than ransomware or destructive activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
36 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with the CreepyDrive OneDrive-based implant that uses Microsoft Graph API and OneDrive for command-and-control tasking and data exfiltration, blending malicious traffic with legitimate Office 365 activity.
Associated with the CreepyDrive OneDrive-based implant that uses the Microsoft Graph API against a user's OneDrive for command-and-control tasking and data exfiltration.
Listed as an associated threat actor in the detection annotation for a Linux usermod root UID set analytic; no specific campaign or activity is described in this reference.
Referenced as a threat actor associated with proxy-based command-and-control behavior relevant to abuse of tunneling/proxy mechanisms.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.