PLATINUM

Also known as: ATK33, DeadlyKiss, Fallow Squall, G0068, GINGERSNAP, PARASITE, PLATINUM, Platinum, RUBYVINE, TwoForOne

PLATINUM is an activity group that has targeted victims since at least 2009. The group has focused on targets associated with governments and related organizations in South and Southeast Asia. Microsoft PLATINUM April 2016

🌍 Country Singapore
📅 Activity 2016 — 2017
🧭 ATT&CK G0068
Defense Government, Administration Diplomacy Intelligence Telecoms
2016
2017

Introduction

PLATINUM is an activity group that has targeted victims since at least 2009. The group has focused on targets associated with governments and related organizations in South and Southeast Asia. Microsoft PLATINUM April 2016

Activities and Tactics

Targeted Sectors: Defense, Government, Administration, Diplomacy, Intelligence, Telecoms

Country of Origin: 🏳️ Singapore

First Seen: 2016

Last Activity: 2017

Notable Campaigns

  • Hellsing

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No atomic indicators are listed in this profile. The APTnotes snapshot indexes 2 public reports that may contain IOCs; see Source Attribution for dataset links.

Malware and Tools

  • Xploit
  • GraphicBooting
  • Hotpatching techniques:
  • CVE-2015-2545:
  • AMT Feature FW evasion:

MITRE ATT&CK Software

Attribution and Evidence

Country of Origin: Singapore Additional attribution information pending cataloguing.

References

[1] mitre-attack [3] Microsoft PLATINUM April 2016 Windows Defender Advanced Threat Hunting Team. (2016, April 29). PLATINUM: Targeted attacks in South and Southeast Asia. Retrieved February 15, 2018.