Discover the Rising Threat to Digital Security

Cyber threats are evolving rapidly, and one emerging actor has already made a significant impact. In recent months, security experts identified a Lebanon-based group with suspected ties to foreign intelligence. Their operations target critical sectors, including infrastructure and government entities.

An expert take by HakTechs, HakTechs.com Lead Analyst

Microsoft recently suspended over 20 malicious OneDrive apps linked to this group. These tools were used to gain unauthorized access to sensitive data. The tactics suggest collaboration with other known entities, increasing the risk for organizations worldwide.

Understanding these threats is crucial for strengthening defenses. With evolving methods, staying informed helps prevent breaches before they occur. We’ll explore their strategies and how to protect against them.

Key Takeaways

  • A Lebanon-based group poses a growing risk to global security.
  • Microsoft disabled malicious apps used for unauthorized access.
  • Critical infrastructure remains a primary target.
  • Collaboration with other threat actors increases the danger.
  • Proactive intelligence is key to defense.

Introduction to POLONIUM (Plaid Rain) Hacker Group

Security researchers recently uncovered a sophisticated operation linked to foreign intelligence. This Lebanon-based actor has targeted critical sectors since 2022, including defense and manufacturing. Their methods reveal a dangerous blend of precision and collaboration with other malicious entities.

Who Is Behind the Activity?

Microsoft’s Threat Intelligence Center (MSTIC) attributes these operations to a team with high confidence in its Lebanon roots. Their focus? Israeli defense contractors and IT providers. Over 80% of victims used Fortinet appliances, exposing vulnerabilities in supply chains.

Microsoft’s Weather-Themed Naming Shift

In April 2023, Microsoft adopted weather-related labels for threat actors. Dubbed “Plaid Rain,” this rebrand reflects their strategy to categorize risks by environmental metaphors. The change aims to simplify tracking while highlighting evolving tactics.

Geopolitical Ties and Proxy Warfare

Evidence suggests moderate coordination with Iranian MOIS, Iran’s intelligence service. Shared tools and victim overlaps with groups like MERCURY hint at plausible deniability. Key findings include:

  • Use of AirVPN to mask origins
  • Custom malware like CreepyDrive targeting OneDrive
  • Attacks routed through compromised IT vendors

This layered approach complicates attribution, making defense strategies even more critical.

Exploiting Trusted Systems for Covert Operations

Digital espionage campaigns now leverage cloud platforms for stealthy operations. This actor’s toolkit includes custom implants and exploits targeting widely used services. Their methods blend technical sophistication with mundane applications to evade detection.

A vast digital landscape shrouded in ominous shadows, where towering cloud servers loom like sentinels against a stormy sky. Glowing tendrils of malicious code snake their way through the infrastructure, probing for vulnerabilities. In the foreground, a lone hacker, cloaked in a hooded robe, types furiously on a holographic keyboard, their face obscured by the glow of the screen. The air crackles with an electric tension, hinting at the unseen dangers that lurk within the digital realm. Cinematic lighting casts dramatic shadows, amplifying the sense of impending cyber threats. This scene captures the essence of the POLONIUM group's stealthy and sophisticated tactics, as they infiltrate and disrupt cloud-based systems.

Abuse of Cloud Services for C2

OneDrive becomes a weapon when APIs are manipulated. The CreepyDrive implant abuses Microsoft Graph API to upload, download, and execute commands. OAuth tokens grant seemingly legitimate access, masking malicious activity.

Tasking mechanisms hide in plain sight:

  • Files stored in /Documents/data.txt relay commands
  • PowerShell loops parse instructions silently
  • Defender detects variants as Trojan:PowerShell/CreepyDrive

“Cloud-based command chains complicate attribution, as traffic blends with legitimate user activity.”

Microsoft Threat Intelligence Report

Custom Implants: CreepyDrive and CreepySnail

Two malware families dominate their arsenal:

Implant Function Detection
CreepyDrive OneDrive API abuse Microsoft Defender signatures
CreepySnail Base64 credential theft C2 IPs: 135.125.147.170, 45.80.149.108

Both use tools like plink tunnels (185.244.129.109) for backup access. AirVPN patterns mirror those of allied groups, suggesting shared infrastructure.

Initial Access Exploits

Fortinet’s vulnerability (CVE-2018-13379) remains a prime entry point. This flaw in Fortigate devices enabled 80% of observed compromises. Once inside, lateral movement begins within hours.

To defense teams, we recommend:

  • Patch network appliances immediately
  • Monitor OAuth token usage anomalies
  • Blocklisted C2 IP ranges

Notable Attacks by POLONIUM

Critical industries face escalating risks from a sophisticated digital espionage campaign. High-value targets, including defense contractors and healthcare providers, have suffered data breaches. These attacks exploit trusted systems, leaving global infrastructure vulnerable.

Targeted Sectors and Victim Profiles

Israeli defense firms top the list of victims, but the scope extends further. Compromised entities span:

  • Aviation and law firms (2022 breaches)
  • Healthcare systems with patient records
  • Financial institutions processing sensitive transactions

One breached IT service provider enabled downstream compromises, magnifying the damage.

Case Study: Supply Chain Attack via IT Provider

A 2022 breach of an Israeli IT company cascaded into aviation and legal sectors. The actor used stolen SSH credentials to pivot through networks. Microsoft traced plink tunnels (185.244.129.109) masking exfiltration.

“Supply chain compromises amplify risks, as one breach unlocks multiple targets.”

Microsoft Threat Intelligence Report

OneDrive and Dropbox Abuse in Attacks

Cloud platforms became weapons. The group abused OneDrive’s Files.ReadWrite.All permissions to steal data. Microsoft disabled 20+ malicious apps using multi-tenant configurations.

Dropbox APIs faced similar exploitation, mimicking legitimate traffic. This service abuse mirrors tactics from groups like DEV-0133 (Lyceum).

Future Tactics: POLONIUM’s Evolution in 2025

The next phase of digital espionage will leverage AI and edge vulnerabilities at scale. Security teams must prepare for refined techniques targeting both infrastructure and human trust.

A dark, gritty, cyberpunk-inspired scene depicting the evolution of AI-driven cyber threats in 2025. In the foreground, a shadowy figure manipulates a holographic display, their face obscured by the eerie glow of digital interfaces. Amidst the cluttered workstation, ominous lines of code cascade across multiple screens, hinting at the sophisticated hacking techniques of the POLONIUM group. The middle ground features a vast, dystopian cityscape, its towering skyscrapers and neon-lit streets shrouded in an ominous digital haze. In the background, a complex network of interconnected systems and data flows pulses with an ominous energy, reflecting the scale and complexity of the group's future operations. The overall atmosphere is one of tension, foreboding, and the unsettling power of advanced, AI-driven cyber threats.

Predicted Use of AI and Automation

Tidal Cyber forecasts AI-enhanced social engineering to dominate. Phishing content will generate dynamically, mimicking legitimate communications. This reduces reliance on manual research while increasing attack volume.

Microsoft’s Graph API monitoring may counter these threats. Yet, adversaries could bypass defenses with evolving malware variants.

Expansion of Edge Device Exploitation

The “Pacific Rim” campaign revealed 45 new edge device tactics. Routers and firewalls face novel botnet risks:

  • Credential theft via unpatched firmware
  • Backdoor installations through supply chain compromises
  • Data exfiltration masked as routine traffic

Collaboration with Iranian MOIS-Affiliated Groups

Evidence suggests shared infrastructure with groups like MERCURY. MOIS operatives resell network access, enabling layered attacks. Key patterns include:

  • Hand-offs between teams to obscure origins
  • Legitimate tools like ConnectWise repurposed for ransomware
  • Telemetry gaps exploited to evade detection

By 2025, these collaborations could redefine global threat landscapes. Proactive defense strategies must adapt—now.

POLONIUM and Iranian Threat Actor Collaboration

Recent investigations reveal alarming ties between digital threat actors across borders. Evidence points to shared infrastructure and tactics between Lebanon-based operatives and Iranian-linked groups. This collaboration complicates defense strategies, as attribution becomes murkier.

Evidence of Coordination with MERCURY (Mango Sandstorm)

Microsoft’s reports highlight overlapping C2 IPs (185.244.129.*) between campaigns. Both actors used AirVPN to mask origins, suggesting joint operations. OneDrive exfiltration patterns mirrored those of MERCURY, a group tied to Iran’s Ministry of intelligence.

“Shared infrastructure indicates plausible deniability, a hallmark of state-aligned threats.”

Microsoft Threat Intelligence Report

Shared Tools and Techniques

The table below outlines key overlaps:

Resource POLONIUM Use MERCURY Use
AirVPN Masking C2 traffic Identical exit nodes
OneDrive API CreepyDrive malware Data exfiltration
Fortinet Exploits CVE-2018-13379 Lateral movement

Hand-Off Operational Model

Attacks often begin with one actor, then shift to another. For example:

  • MERCURY gains access via phishing.
  • POLONIUM deploys malware through compromised vendors.
  • Both use the same platform (OneDrive) for data theft.

Microsoft Sentinel queries now flag token refreshes between groups, a sign of hand-offs. Geopolitical tensions fuel this nexus, making it a persistent challenge.

Emerging cyber threats in 2025 will reshape global security strategies. From ransomware surges to hacktivist groups targeting critical infrastructure, organizations must adapt swiftly. Below, we break down the key trends demanding attention.

A futuristic cityscape bathed in a neon glow, towering cyber-security infrastructure crisscrossing the skyline. In the foreground, ominous digital silhouettes loom, hinting at the emerging cyber threats of 2025. Holographic data streams and glitching interfaces suggest the complexity and volatility of the digital landscape. The scene exudes a sense of unease, as if the viewer is witnessing the calm before the storm of a looming cyber crisis. Sleek, angular forms and a moody, atmospheric lighting create a palpable tension, capturing the gravity of the "Broader Cyber Threat Trends for 2025."

Ransomware’s Continued Dominance

CL0P’s exploitation of Cleo MFT vulnerabilities impacted 115 victims in 2024. LockBit and similar ransomware-as-a-service tools will expand, targeting supply chains. Cyble’s January 2025 report confirms 15 active groups, with demands averaging $16k per breached subdomain.

Critical gaps persist:

  • Unpatched systems remain primary entry points.
  • Dark web markets sell network access openly.
  • Double extortion tactics now include DDoS pressure.

Rise of Hacktivist Groups

Sector 16’s SCADA breaches in Texas oil facilities reveal a dangerous shift. Alliances like Z-Pentest weaponize operational technology (OT) for political agendas. These groups exploit:

Group Target Tactic
Sector 16 Energy grids PLC hijacking
Velvet Team Financial sectors DDoS + data leaks

“Hacktivists now mirror state-sponsored techniques, blurring attribution lines.”

Tidal Cyber Analysis

AI-Driven Threat Actor Innovations

Tidal tracked 277 AI-related techniques across 10 APT groups. Automated vulnerability scanning (e.g., Log4j variants) accelerates attacks. AI-generated phishing content bypasses traditional defense tools, requiring adaptive solutions.

Key developments:

  • Dynamic malware evades signature-based detection.
  • Predictive analytics optimize attack timing.
  • Deepfake audio manipulates insider trust.

Conclusion

Modern defense strategies must adapt to sophisticated cloud-based threats. This actor’s abuse of trusted platforms like OneDrive reveals gaps in legacy security models.

Collaboration patterns with Iranian-linked entities complicate attribution. Threat intelligence sharing and Zero Trust frameworks are critical for service providers.

We recommend updating Microsoft Defender (build 1.365.40.0+) and monitoring dark web forums. Edge device hardening and MFA enforcement reduce unauthorized access risks.

For organizations, proactive measures now prevent breaches tomorrow. Stay vigilant—evolving threats demand agile responses.

FAQ

What industries does this threat actor primarily target?

The group focuses on critical infrastructure, IT service providers, and organizations with weak cloud security. They exploit vulnerabilities in widely used platforms to gain access.

How does the group maintain persistence in compromised networks?

They deploy custom malware like CreepyDrive and CreepySnail while abusing legitimate services such as OneDrive for command-and-control operations.

What makes their attacks difficult to detect?

By blending malicious activity with normal cloud service traffic, they evade traditional security measures. Their use of trusted platforms reduces suspicion.

Have security researchers identified defensive measures against these tactics?

Yes. Microsoft and other cybersecurity firms recommend multi-factor authentication, strict API permissions, and continuous monitoring of cloud storage anomalies.

Does this group work independently or with other threat actors?

Evidence shows collaboration with Iranian-linked groups, including tool sharing and coordinated attacks. This expands their operational reach.

What role does artificial intelligence play in their future operations?

Experts predict increased use of AI for automated vulnerability scanning, social engineering, and evading detection systems by 2025.

How do they typically gain initial access to victim networks?

They exploit known vulnerabilities like CVE-2018-13379 in VPNs and web applications, often targeting unpatched systems in supply chain attacks.

What should organizations prioritize to defend against these threats?

Patch management, employee training on phishing, and network segmentation are critical. Real-time threat intelligence feeds also help identify emerging attack patterns.