Polonium is a Lebanon-based espionage actor tracked since February 2022 that has compromised 20+ Israeli organizations across manufacturing, IT, defense, engineering, law, and media, and is assessed by Microsoft with moderate confidence to coordinate with Iran's MOIS.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Polonium (Microsoft's naming; MITRE tracks it as G1005, ESET as Plaid Rain) surfaced publicly in June 2022 when Microsoft's MSTIC disclosed intrusions against more than 20 Israeli organizations. Microsoft assessed with moderate confidence that Polonium coordinates with multiple actors affiliated with Iran's Ministry of Intelligence and Security (MOIS), inferred from victim overlap and shared tooling/techniques rather than a confirmed command relationship — an attribution nuance worth preserving, as Polonium itself is operated from Lebanon.
Initial access has centered on exploitation of internet-facing Fortinet FortiOS SSL-VPN appliances (consistent with CVE-2018-13379 path-traversal credential exposure), giving the group valid-account footholds into targeted networks. Post-compromise, Polonium is defined by its custom 'Creepy' toolset: the CreepySnail PowerShell implant plus the CreepyDrive and CreepyBox backdoors, which abuse legitimate cloud services (OneDrive and Dropbox) for command-and-control and data exfiltration — a low-noise living-off-trusted-services pattern that blends with normal enterprise traffic. MITRE maps the group to trusted-relationship abuse, proxying, bidirectional web-service C2, and exfiltration to cloud storage.
MENA targeting is effectively Israel-exclusive. ESET, tracking the group as Plaid Rain, documented roughly a dozen Israeli victims in late 2022 spanning engineering, IT, law, communications, marketing, and insurance, and noted evidence of at least seven distinct custom backdoors. Several victims were also targeted by other Iran-linked actors, reinforcing the assessed MOIS coordination.
Standalone Polonium-branded reporting tapered after 2022–2023; the group has not been prominently re-reported under its own name into 2025–2026, and later activity may be folded into broader Iran-nexus clusters. Its last independently confirmed activity is assessed at 2023.