ATT&CKGroupsPOLONIUM

POLONIUM

G1005

Threat group.View on attack.mitre.org

About this group

POLONIUM is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at least February 2022. Security researchers assess POLONIUM has coordinated their operations with multiple actors affiliated with Iran’s Ministry of Intelligence and Security (MOIS), based on victim overlap as well as common techniques and tooling.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1078
Valid Accounts

POLONIUM has used valid compromised credentials to gain access to victim environments.

T1090
Proxy

POLONIUM has used the AirVPN service for operational activity.

T1102.002
Bidirectional Communication

POLONIUM has used OneDrive and DropBox for C2.

T1199
Trusted Relationship

POLONIUM has used compromised credentials from an IT company to target downstream customers including a law firm and aviation company.

T1567.002
Exfiltration to Cloud Storage

POLONIUM has exfiltrated stolen data to POLONIUM-owned OneDrive and Dropbox accounts.

T1583.006
Web Services

POLONIUM has created and used legitimate Microsoft OneDrive accounts for their operations.

T1588.002
Tool

POLONIUM has obtained and used tools such as AirVPN and plink in their operations.

Software2

Campaigns0

None recorded.

References1

  1. Microsoft POLONIUM June 2022 Open source
    Microsoft. (2022, June 2). Exposing POLONIUM activity and infrastructure targeting Israeli organizations. Retrieved July 1, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.