POLONIUM, also referred to as Plaid Rain and Incendiary Jackal, is a threat actor first documented in 2022 that primarily targets entities in Israel, including organizations in the defense, government, manufacturing, and financial sectors. The content describes the actor as Lebanon-based and notes that its activity indicates potential coordination with Iran-nexus actors affiliated with Iran’s Ministry of Intelligence and Security (MOIS). POLONIUM is suspected to obtain initial access through vulnerability exploitation, downstream compromises, and stolen credentials. Reported activity includes use of compromised credentials from an IT company to target downstream customers, including a law firm and an aviation company. The actor has used cloud services for operations, including OneDrive and Dropbox for command and control and exfiltration, and has created and used legitimate Microsoft OneDrive accounts as part of its operations. The content also states that POLONIUM exfiltrated stolen data to actor-owned OneDrive and Dropbox accounts. Additional tooling and tradecraft directly mentioned include use of AirVPN for operational activity and use of plink. The content also associates POLONIUM with MITRE ATT&CK technique T1090 (Proxy) and T1567.002 (Exfiltration to Cloud Storage).
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat actor associated with proxy-based command-and-control behavior relevant to the detection of Microsoft Devtunnels execution.
Associated with exfiltration to cloud storage, specifically the use of Azure Storage utilities such as AzCopy or Storage Explorer for staging or extracting sensitive data over trusted cloud channels.
Listed as a threat actor associated with the ATT&CK technique T1567.002 (Exfiltration to Cloud Storage) in the context of mounting a OneDrive share via net.exe/net1.exe for possible staging, access, or exfiltration.
Referenced as a threat actor associated with proxy-based command-and-control behavior relevant to abuse of tunneling/proxy mechanisms.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.