Overview 26 indicators
POLONIUM is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at least February 2022. Security researchers assess POLONIUM has coordinated their operations with multiple actors affiliated with Iran’s Ministry of Intelligence and Security (MOIS), based on victim overlap as well as common techniques and tooling.
| ipv4 | 16 | G1005.json |
| url | 5 | G1005.json |
| url_path | 5 | G1005.json |
Techniques 7 ATT&CK
Open in ATT&CK Navigator → or download the layer (7 techniques, layer 4.5)
- T1078 Valid Accounts
- T1090 Proxy
- T1102.002 Bidirectional Communication
- T1199 Trusted Relationship
- T1567.002 Exfiltration to Cloud Storage
- T1583.006 Web Services
- T1588.002 Tool
Software 2
Principal sources 5 reports
Ranked by how many of this actor's indicators each report brought in.
- 20welivesecurity.com/2022/10/11/polonium-targets-israel-cree…
- 20github.com/eset/malware-ioc/tree/master/polonium
- 6twitter.com/k3yp0d/status/1658089065885884420
- 6virustotal.com/gui/file/70e4b5d32abfa9134122ae36ba64d0…
- 6virustotal.com/gui/file/a81247a8a16bc1c0077346dacfa005…
Timeline 26 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
twitter.com/k3yp0d/status/1658089065885884420 · virustotal.com/gui/file/70e4b5d32abfa9134122ae36ba64d0… · virustotal.com/gui/file/a81247a8a16bc1c0077346dacfa005…
ipv4 185.244.129.216:8080 url_path /IZJXKKqgAJ?g7Bh7t= url_path /t2kmBOZdMn/ url_path /t2kmBOZdMn/IZJXKKqgAJ?g7Bh7t= url_path /ui/chk?mactok= url_path /ui/insrt?mactok= -
welivesecurity.com/2022/10/11/polonium-targets-israel-cree… · github.com/eset/malware-ioc/tree/master/polonium
ipv4 146.70.86.6:1433 ipv4 185.203.119.99:8080 ipv4 185.244.129.216:5055 ipv4 185.244.129.79:63047 ipv4 195.166.100.23:5055 ipv4 45.137.148.7:2121 ipv4 45.80.148.119:8080 ipv4 45.80.148.167:21 ipv4 45.80.148.167:5055 ipv4 45.80.148.186:8080 ipv4 45.80.149.108:8080 ipv4 45.80.149.154:1302 ipv4 45.80.149.154:21 ipv4 45.80.149.22:8080 ipv4 45.80.149.68:63047 url http://212.73.150.174 url http://37.120.233.89 url http://45.80.149.71 url http://51.83.246.73 url http://94.156.189.103
Further reading 8
- attack.mitre.org/groups/G1005
- learn.microsoft.com/en-us/microsoft-365/security/intelligen…
- microsoft.com/security/blog/2022/06/02/exposing-polon…
- twitter.com/k3yp0d/status/1658089065885884420
- github.com/eset/malware-ioc/tree/master/polonium
- virustotal.com/gui/file/70e4b5d32abfa9134122ae36ba64d0…
- welivesecurity.com/2022/10/11/polonium-targets-israel-cree…
- virustotal.com/gui/file/a81247a8a16bc1c0077346dacfa005…