By focusing only on Israeli targets, POLONIUM targets organizations across various verticals. Microsoft believes that this is an operational group based in Lebanon that coordinates its activities with entities affiliated with the Iranian Ministry of Intelligence and Security. The group has developed ad hoc tools to collect information. For command and control operations it illicitly exploits the most well-known cloud services such as Dropbox, OneDrive and Mega
Researchers of ESET, a global leader in the cybersecurity market, recently analyzed custom backdoors and previously undocumented cyberespionage tools distributed in Israel by the APT POLONIUM group. ESET has named the five backdoors with the suffix “-Creep”. According to ESET telemetry, POLONIUM has targeted more than a dozen organizations in Israel since at least September 2021, with the group's most recent actions seen in September this year. The verticals targeted by this group range from engineering, information technology, justice, communications, branding and marketing, media, insurance and social services. POLONIUM is a cyberespionage group first documented by Microsoft in June 2022. The company believes the group is based in Lebanon and coordinates its activities with other entities affiliated with the Iranian Ministry of Intelligence and Security.
According to ESET Research, POLONIUM is a very active threat player that has a large arsenal of malware tools that are constantly updated and developed. A common feature of several tools is the use of cloud services such as Dropbox, Mega and OneDrive for command and control (C&C) activities. Official information and reporting on POLONIUM is sparse and sparse, likely because the group's attacks are highly targeted and the initial compromise vector is unknown.
"The numerous versions and modifications introduced by POLONIUM in its custom tools demonstrate a continuous and long-term effort to spy on the organizations that the group has chosen as targets. ESET can deduce from the toolset they use that they are interested in collecting confidential data. The group does not appear to be engaged in sabotage or ransomware actions," he says Matías Porolli, researcher at ESET which analyzed the malware.
POLONIUM's toolset consists of seven custom backdoors: CreepyDrive, which leverages OneDrive and Dropbox cloud services for C&C; CreepySnail, which executes commands received from the attackers' infrastructure; DeepCreep and MegaCreep, which use the Dropbox and Mega file storage services, respectively; and FlipCreep, TechnoCreep, and PapaCreep, which receive commands from attackers' servers. The group has also developed several custom modules to spy on their targets, taking screenshots, recording keystrokes, spying on the webcam, opening reverse shells, exfiltrating files, and more.
"Most of the malicious modules in the group are small in size, with limited functionality. In one case the attackers used one module to capture screenshots and another to upload them to the C&C server. Similarly, they prefer to split the code of their backdoors, distributing the malicious functionality into several modestly sized DLLs, perhaps believing that security professionals or researchers do not thoroughly analyze the entire attack sequence," explains Porolli.
For further technical information on POLONIUM, consult the blog “Polonium targets Israel with Creepy malware” su WeLiveSecurity.






