POLONIUM
Also tracked as Plaid Rain
POLONIUM is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at least February 2022. Security researchers assess POLONIUM has coordinated their operations with multiple actors affiliated with Iran’s Ministry of Intelligence and Security (MOIS), based on victim overlap as well as common techniques and tooling.
- Documented techniques
- 7
- Assessed origin
- Lebanon
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
resource development2
initial access1
command and control2
exfiltration1
stealth1
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.