logo

POLONIUM: Proxy Warfare and Iran’s Cyber Strategy

ID: 9b30419f-5215-59bd-a09c-3f53e4eae2c3

STIX ID: report--9b30419f-5215-59bd-a09c-3f53e4eae2c3

Feed Name: ReliaQuest Blog

Threat Score
85/100

Date Published: 2022-06-20

Date Updated: 2026-04-29

...
...

Microsoft-tracked APT “POLONIUM,” operating from Lebanon since early 2022 and suspected of Iranian support, has targeted over 20 Israeli organizations and an inter-governmental entity using custom tooling (PowerShell implant “CreepySnail”), malicious OneDrive applications for C2, AirVPN, and exploitation of Fortinet CVE-2018-13379; Microsoft has issued mitigations and suspended the malicious OneDrive apps. The report frames POLONIUM as a likely state-backed proxy actor, highlights supply-chain and repeated targeting overlapping with Iranian-linked group MuddyWater, and places the activity in the context of Iran’s broader proxy strategy in the region.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.