POLONIUM: Proxy Warfare and Iranâs Cyber Strategy
ID: 9b30419f-5215-59bd-a09c-3f53e4eae2c3
STIX ID: report--9b30419f-5215-59bd-a09c-3f53e4eae2c3
Feed Name: ReliaQuest Blog
Microsoft-tracked APT “POLONIUM,” operating from Lebanon since early 2022 and suspected of Iranian support, has targeted over 20 Israeli organizations and an inter-governmental entity using custom tooling (PowerShell implant “CreepySnail”), malicious OneDrive applications for C2, AirVPN, and exploitation of Fortinet CVE-2018-13379; Microsoft has issued mitigations and suspended the malicious OneDrive apps. The report frames POLONIUM as a likely state-backed proxy actor, highlights supply-chain and repeated targeting overlapping with Iranian-linked group MuddyWater, and places the activity in the context of Iran’s broader proxy strategy in the region.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
