ATT&CKGroupsPLATINUM

PLATINUM

G0068

Threat group.View on attack.mitre.org

About this group

PLATINUM is an activity group that has targeted victims since at least 2009. The group has focused on targets associated with governments and related organizations in South and Southeast Asia.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1003.001
LSASS Memory

PLATINUM has used keyloggers that are also capable of dumping credentials.

T1036
Masquerading

PLATINUM has renamed rar.exe to avoid detection.

T1055
Process Injection

PLATINUM has used various methods of process injection including hot patching.

T1056.001
Keylogging

PLATINUM has used several different keyloggers.

T1056.004
Credential API Hooking

PLATINUM is capable of using Windows hook interfaces for information gathering such as credential access.

T1068
Exploitation for Privilege Escalation

PLATINUM has leveraged a zero-day vulnerability to escalate privileges.

T1095
Non-Application Layer Protocol

PLATINUM has used the Intel® Active Management Technology (AMT) Serial-over-LAN (SOL) channel for command and control.

T1105
Ingress Tool Transfer

PLATINUM has transferred files using the Intel® Active Management Technology (AMT) Serial-over-LAN (SOL) channel.

T1189
Drive-by Compromise

PLATINUM has sometimes used drive-by attacks against vulnerable browser plugins.

T1204.002
Malicious File

PLATINUM has attempted to get users to open malicious files by sending spearphishing emails with attachments to victims.

T1566.001
Spearphishing Attachment

PLATINUM has sent spearphishing emails with attachments to victims as its primary initial access vector.

Software3

Campaigns0

None recorded.

References1

  1. Microsoft PLATINUM April 2016 Open source
    Windows Defender Advanced Threat Hunting Team. (2016, April 29). PLATINUM: Targeted attacks in South and Southeast Asia. Retrieved February 15, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.