Polonium is a Lebanon-based APT group that exclusively targets Israeli companies, and was first detected in June 2022.
Analysts at Deep Instinct have analyzed and concluded that Polonium uses a multistep attack flow of loaders and separation of components to make detection of malicious activities harder.
Deep Instinct has further analyzed ESET research into the APT and has found three additional samples which they have identified as loaders, used to load not only the MegaCreep backdoor, but potential other backdoors and tools from the Polonium arsenal.
Polonium reuses the same Loader files on multiple computers, but randomizes the paths where they are executed from.