POLONIUM
Microsoft successfully detected and disabled attack activity abusing OneDrive by a previously undocumented Lebanon-based activity group Microsoft Threat Intelligence Center (MSTIC) tracks as POLONIUM.
POLONIUM is a Lebanon-based cyber espionage group targeting Israel's defense and healthcare sectors using CreepyDrive malware.
POLONIUM is a Lebanon-based cyber espionage group targeting Israel. It primarily focuses on the defense industrial base, healthcare, financial services, government agencies, and information technology sectors. The group uses trusted relationships for initial access and leverages CreepyDrive and CreepySnail malware to exfiltrate data to cloud storage. Defenders should prioritize monitoring for cloud-based data exfiltration activities, particularly to OneDrive.
Microsoft successfully detected and disabled attack activity abusing OneDrive by a previously undocumented Lebanon-based activity group Microsoft Threat Intelligence Center (MSTIC) tracks as POLONIUM.
Monitor and block suspicious Web Services and Tool acquisition activities.
Monitor and validate suspicious connections coming through Trusted Relationship.
Detect and analyze unusual activities using Valid Accounts.
Monitor and block suspicious network activities using Proxy and Bidirectional Communication.
Detect and prevent suspicious Exfiltration activities to Cloud Storage.
POLONIUM primarily targets the defense industrial base, healthcare, financial services, agriculture, information technology, and government agencies.
The group uses CreepyDrive and CreepySnail malware to exfiltrate data to cloud storage.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.