Cyber threats are evolving rapidly, and one emerging actor has already made a significant impact. In recent months, security experts identified a Lebanon-based group with suspected ties to foreign intelligence. Their operations target critical sectors, including infrastructure and government entities.
Microsoft recently suspended over 20 malicious OneDrive apps linked to this group. These tools were used to gain unauthorized access to sensitive data. The tactics suggest collaboration with other known entities, increasing the risk for organizations worldwide.
Understanding these threats is crucial for strengthening defenses. With evolving methods, staying informed helps prevent breaches before they occur. We’ll explore their strategies and how to protect against them.
Key Takeaways
- A Lebanon-based group poses a growing risk to global security.
- Microsoft disabled malicious apps used for unauthorized access.
- Critical infrastructure remains a primary target.
- Collaboration with other threat actors increases the danger.
- Proactive intelligence is key to defense.
Introduction to POLONIUM (Plaid Rain) Hacker Group
Security researchers recently uncovered a sophisticated operation linked to foreign intelligence. This Lebanon-based actor has targeted critical sectors since 2022, including defense and manufacturing. Their methods reveal a dangerous blend of precision and collaboration with other malicious entities.
Who Is Behind the Activity?
Microsoft’s Threat Intelligence Center (MSTIC) attributes these operations to a team with high confidence in its Lebanon roots. Their focus? Israeli defense contractors and IT providers. Over 80% of victims used Fortinet appliances, exposing vulnerabilities in supply chains.
Microsoft’s Weather-Themed Naming Shift
In April 2023, Microsoft adopted weather-related labels for threat actors. Dubbed “Plaid Rain,” this rebrand reflects their strategy to categorize risks by environmental metaphors. The change aims to simplify tracking while highlighting evolving tactics.
Geopolitical Ties and Proxy Warfare
Evidence suggests moderate coordination with Iranian MOIS, Iran’s intelligence service. Shared tools and victim overlaps with groups like MERCURY hint at plausible deniability. Key findings include:
- Use of AirVPN to mask origins
- Custom malware like CreepyDrive targeting OneDrive
- Attacks routed through compromised IT vendors
This layered approach complicates attribution, making defense strategies even more critical.
Exploiting Trusted Systems for Covert Operations
Digital espionage campaigns now leverage cloud platforms for stealthy operations. This actor’s toolkit includes custom implants and exploits targeting widely used services. Their methods blend technical sophistication with mundane applications to evade detection.

Abuse of Cloud Services for C2
OneDrive becomes a weapon when APIs are manipulated. The CreepyDrive implant abuses Microsoft Graph API to upload, download, and execute commands. OAuth tokens grant seemingly legitimate access, masking malicious activity.
Tasking mechanisms hide in plain sight:
- Files stored in /Documents/data.txt relay commands
- PowerShell loops parse instructions silently
- Defender detects variants as Trojan:PowerShell/CreepyDrive
“Cloud-based command chains complicate attribution, as traffic blends with legitimate user activity.”
Custom Implants: CreepyDrive and CreepySnail
Two malware families dominate their arsenal:
| Implant | Function | Detection |
|---|---|---|
| CreepyDrive | OneDrive API abuse | Microsoft Defender signatures |
| CreepySnail | Base64 credential theft | C2 IPs: 135.125.147.170, 45.80.149.108 |
Both use tools like plink tunnels (185.244.129.109) for backup access. AirVPN patterns mirror those of allied groups, suggesting shared infrastructure.
Initial Access Exploits
Fortinet’s vulnerability (CVE-2018-13379) remains a prime entry point. This flaw in Fortigate devices enabled 80% of observed compromises. Once inside, lateral movement begins within hours.
To defense teams, we recommend:
- Patch network appliances immediately
- Monitor OAuth token usage anomalies
- Blocklisted C2 IP ranges
Notable Attacks by POLONIUM
Critical industries face escalating risks from a sophisticated digital espionage campaign. High-value targets, including defense contractors and healthcare providers, have suffered data breaches. These attacks exploit trusted systems, leaving global infrastructure vulnerable.
Targeted Sectors and Victim Profiles
Israeli defense firms top the list of victims, but the scope extends further. Compromised entities span:
- Aviation and law firms (2022 breaches)
- Healthcare systems with patient records
- Financial institutions processing sensitive transactions
One breached IT service provider enabled downstream compromises, magnifying the damage.
Case Study: Supply Chain Attack via IT Provider
A 2022 breach of an Israeli IT company cascaded into aviation and legal sectors. The actor used stolen SSH credentials to pivot through networks. Microsoft traced plink tunnels (185.244.129.109) masking exfiltration.
“Supply chain compromises amplify risks, as one breach unlocks multiple targets.”
OneDrive and Dropbox Abuse in Attacks
Cloud platforms became weapons. The group abused OneDrive’s Files.ReadWrite.All permissions to steal data. Microsoft disabled 20+ malicious apps using multi-tenant configurations.
Dropbox APIs faced similar exploitation, mimicking legitimate traffic. This service abuse mirrors tactics from groups like DEV-0133 (Lyceum).
Future Tactics: POLONIUM’s Evolution in 2025
The next phase of digital espionage will leverage AI and edge vulnerabilities at scale. Security teams must prepare for refined techniques targeting both infrastructure and human trust.

Predicted Use of AI and Automation
Tidal Cyber forecasts AI-enhanced social engineering to dominate. Phishing content will generate dynamically, mimicking legitimate communications. This reduces reliance on manual research while increasing attack volume.
Microsoft’s Graph API monitoring may counter these threats. Yet, adversaries could bypass defenses with evolving malware variants.
Expansion of Edge Device Exploitation
The “Pacific Rim” campaign revealed 45 new edge device tactics. Routers and firewalls face novel botnet risks:
- Credential theft via unpatched firmware
- Backdoor installations through supply chain compromises
- Data exfiltration masked as routine traffic
Collaboration with Iranian MOIS-Affiliated Groups
Evidence suggests shared infrastructure with groups like MERCURY. MOIS operatives resell network access, enabling layered attacks. Key patterns include:
- Hand-offs between teams to obscure origins
- Legitimate tools like ConnectWise repurposed for ransomware
- Telemetry gaps exploited to evade detection
By 2025, these collaborations could redefine global threat landscapes. Proactive defense strategies must adapt—now.
POLONIUM and Iranian Threat Actor Collaboration
Recent investigations reveal alarming ties between digital threat actors across borders. Evidence points to shared infrastructure and tactics between Lebanon-based operatives and Iranian-linked groups. This collaboration complicates defense strategies, as attribution becomes murkier.
Evidence of Coordination with MERCURY (Mango Sandstorm)
Microsoft’s reports highlight overlapping C2 IPs (185.244.129.*) between campaigns. Both actors used AirVPN to mask origins, suggesting joint operations. OneDrive exfiltration patterns mirrored those of MERCURY, a group tied to Iran’s Ministry of intelligence.
“Shared infrastructure indicates plausible deniability, a hallmark of state-aligned threats.”
Shared Tools and Techniques
The table below outlines key overlaps:
| Resource | POLONIUM Use | MERCURY Use |
|---|---|---|
| AirVPN | Masking C2 traffic | Identical exit nodes |
| OneDrive API | CreepyDrive malware | Data exfiltration |
| Fortinet Exploits | CVE-2018-13379 | Lateral movement |
Hand-Off Operational Model
Attacks often begin with one actor, then shift to another. For example:
- MERCURY gains access via phishing.
- POLONIUM deploys malware through compromised vendors.
- Both use the same platform (OneDrive) for data theft.
Microsoft Sentinel queries now flag token refreshes between groups, a sign of hand-offs. Geopolitical tensions fuel this nexus, making it a persistent challenge.
Broader Cyber Threat Trends for 2025
Emerging cyber threats in 2025 will reshape global security strategies. From ransomware surges to hacktivist groups targeting critical infrastructure, organizations must adapt swiftly. Below, we break down the key trends demanding attention.

Ransomware’s Continued Dominance
CL0P’s exploitation of Cleo MFT vulnerabilities impacted 115 victims in 2024. LockBit and similar ransomware-as-a-service tools will expand, targeting supply chains. Cyble’s January 2025 report confirms 15 active groups, with demands averaging $16k per breached subdomain.
Critical gaps persist:
- Unpatched systems remain primary entry points.
- Dark web markets sell network access openly.
- Double extortion tactics now include DDoS pressure.
Rise of Hacktivist Groups
Sector 16’s SCADA breaches in Texas oil facilities reveal a dangerous shift. Alliances like Z-Pentest weaponize operational technology (OT) for political agendas. These groups exploit:
| Group | Target | Tactic |
|---|---|---|
| Sector 16 | Energy grids | PLC hijacking |
| Velvet Team | Financial sectors | DDoS + data leaks |
“Hacktivists now mirror state-sponsored techniques, blurring attribution lines.”
AI-Driven Threat Actor Innovations
Tidal tracked 277 AI-related techniques across 10 APT groups. Automated vulnerability scanning (e.g., Log4j variants) accelerates attacks. AI-generated phishing content bypasses traditional defense tools, requiring adaptive solutions.
Key developments:
- Dynamic malware evades signature-based detection.
- Predictive analytics optimize attack timing.
- Deepfake audio manipulates insider trust.
Conclusion
Modern defense strategies must adapt to sophisticated cloud-based threats. This actor’s abuse of trusted platforms like OneDrive reveals gaps in legacy security models.
Collaboration patterns with Iranian-linked entities complicate attribution. Threat intelligence sharing and Zero Trust frameworks are critical for service providers.
We recommend updating Microsoft Defender (build 1.365.40.0+) and monitoring dark web forums. Edge device hardening and MFA enforcement reduce unauthorized access risks.
For organizations, proactive measures now prevent breaches tomorrow. Stay vigilant—evolving threats demand agile responses.