Windows Defender Advanced Threat Hunting Team. (2016, April 29). PLATINUM: Targeted attacks in South and Southeast Asia. Retrieved February 15, 2018.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupPLATINUM | PLATINUM has used keyloggers that are also capable of dumping credentials. |
| T1007 System Service Discovery |
MalwareJPIN | JPIN can list running services. |
| T1012 Query Registry |
MalwareJPIN | JPIN can enumerate Registry keys. |
| T1016 System Network Configuration Discovery |
MalwareJPIN | JPIN can obtain network information, including DNS, IP, and proxies. |
| T1027 Obfuscated Files or Information |
MalwareJPIN | A JPIN uses a encrypted and compressed payload that is disguised as a bitmap within the resource section of the installer. |
| T1029 Scheduled Transfer |
MalwareDipsind | Dipsind can be configured to only run during normal working hours, which would make its communications harder to distinguish from normal traffic. |
| T1033 System Owner/User Discovery |
MalwareJPIN | JPIN can obtain the victim user name. |
| T1055 Process Injection |
MalwareJPIN | JPIN can inject content into lsass.exe to load a module. |
| T1055 Process Injection |
GroupPLATINUM | PLATINUM has used various methods of process injection including hot patching. |
| T1056.001 Keylogging |
GroupPLATINUM | PLATINUM has used several different keyloggers. |
| T1056.001 Keylogging |
MalwareJPIN | JPIN contains a custom keylogger. |
| T1056.004 Credential API Hooking |
GroupPLATINUM | PLATINUM is capable of using Windows hook interfaces for information gathering such as credential access. |
| T1057 Process Discovery |
MalwareJPIN | JPIN can list running processes. |
| T1059.003 Windows Command Shell |
Malwareadbupd | adbupd can run a copy of cmd.exe. |
| T1059.003 Windows Command Shell |
MalwareDipsind | Dipsind can spawn remote shells. |
| T1059.003 Windows Command Shell |
MalwareJPIN | JPIN can use the command-line utility cacls.exe to change file permissions. |
| T1068 Exploitation for Privilege Escalation |
GroupPLATINUM | PLATINUM has leveraged a zero-day vulnerability to escalate privileges. |
| T1069.001 Local Groups |
MalwareJPIN | JPIN can obtain the permissions of the victim user. |
| T1070.004 File Deletion |
MalwareJPIN | JPIN's installer/uninstaller component deletes itself if it encounters a version of Windows earlier than Windows XP or identifies security-related processes running. |
| T1071.001 Web Protocols |
MalwareDipsind | Dipsind uses HTTP for C2. |
| T1071.002 File Transfer Protocols |
MalwareJPIN | JPIN can communicate over FTP. |
| T1071.003 Mail Protocols |
MalwareJPIN | JPIN can send email over SMTP. |
| T1082 System Information Discovery |
MalwareJPIN | JPIN can obtain system information such as OS version and disk space. |
| T1083 File and Directory Discovery |
MalwareJPIN | JPIN can enumerate drives and their types. It can also change file permissions using cacls.exe. |
| T1105 Ingress Tool Transfer |
MalwareDipsind | Dipsind can download remote files. |
| T1105 Ingress Tool Transfer |
MalwareJPIN | JPIN can download files and upgrade itself. |
| T1132.001 Standard Encoding |
MalwareDipsind | Dipsind encodes C2 traffic with base64. |
| T1189 Drive-by Compromise |
GroupPLATINUM | PLATINUM has sometimes used drive-by attacks against vulnerable browser plugins. |
| T1197 BITS Jobs |
MalwareJPIN | A JPIN variant downloads the backdoor payload via the BITS service. |
| T1204.002 Malicious File |
GroupPLATINUM | PLATINUM has attempted to get users to open malicious files by sending spearphishing emails with attachments to victims. |
| T1222.001 Windows Permissions |
MalwareJPIN | JPIN can use the command-line utility cacls.exe to change file permissions. |
| T1518.001 Security Software Discovery |
MalwareJPIN | JPIN checks for the presence of certain security-related processes and deletes its installer/uninstaller component if it identifies any of them. |
| T1546.003 Windows Management Instrumentation Event Subscription |
Malwareadbupd | adbupd can use a WMI script to achieve persistence. |
| T1547.004 Winlogon Helper DLL |
MalwareDipsind | A Dipsind variant registers as a Winlogon Event Notify DLL to establish persistence. |
| T1566.001 Spearphishing Attachment |
GroupPLATINUM | PLATINUM has sent spearphishing emails with attachments to victims as its primary initial access vector. |
| T1573.001 Symmetric Cryptography |
MalwareDipsind | Dipsind encrypts C2 data with AES256 in ECB mode. |
| T1573.002 Asymmetric Cryptography |
Malwareadbupd | adbupd contains a copy of the OpenSSL library to encrypt C2 traffic. |
| T1685 Disable or Modify Tools |
MalwareJPIN | JPIN can lower security settings by changing Registry keys. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.