Threat group.View on attack.mitre.org
POLONIUM is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at least February 2022. Security researchers assess POLONIUM has coordinated their operations with multiple actors affiliated with Iran’s Ministry of Intelligence and Security (MOIS), based on victim overlap as well as common techniques and tooling.
| Technique | Procedure example |
|---|---|
| T1078 Valid Accounts |
POLONIUM has used valid compromised credentials to gain access to victim environments. |
| T1090 Proxy |
POLONIUM has used the AirVPN service for operational activity. |
| T1102.002 Bidirectional Communication |
POLONIUM has used OneDrive and DropBox for C2. |
| T1199 Trusted Relationship |
POLONIUM has used compromised credentials from an IT company to target downstream customers including a law firm and aviation company. |
| T1567.002 Exfiltration to Cloud Storage |
POLONIUM has exfiltrated stolen data to POLONIUM-owned OneDrive and Dropbox accounts. |
| T1583.006 Web Services |
POLONIUM has created and used legitimate Microsoft OneDrive accounts for their operations. |
| T1588.002 Tool |
POLONIUM has obtained and used tools such as AirVPN and plink in their operations. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.