PLATINUM
Overview
PLATINUM is an activity group that has targeted victims since at least 2009. The group has focused on targets associated with governments and related organizations in South and Southeast Asia.
Naming & attribution
PLATINUM is tracked under 1 names across the industry. It uses 11 documented ATT&CK techniques — more than 32% of the 174 groups tracked here. Activity attributed since at least 2009.
| Name | First reported by |
|---|---|
| PLATINUM | Windows Defender Advanced Threat Hunting Team |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1056.004Credential API Hooking — used by 1 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Ajax Security Team Iran — 4 shared techniques (31% overlap)
- Nomadic Octopus Russia — 4 shared techniques (29% overlap)
- Elderwood China — 4 shared techniques (25% overlap)
- Whitefly — 4 shared techniques (25% overlap)
- Tonto Team China — 5 shared techniques (24% overlap)
- BITTER — 5 shared techniques (23% overlap)
Targets
Defense · Diplomacy · Government · Intelligence · Telecommunications
Capabilities
- Custom malware/implant development — ATT&CK: 3 attributed custom malware families
TTPs — 11 techniques across 7 tactics
Initial Access
-
T1189Drive-by Compromise -
T1566.001Spearphishing Attachment
Execution
-
T1204.002Malicious File
Privilege Escalation
Stealth
-
T1036Masquerading -
T1055Process Injection
Credential Access
-
T1003.001LSASS Memory
Collection
-
T1056.001Keylogging -
T1056.004Credential API Hooking
Command and Control
-
T1095Non-Application Layer Protocol -
T1105Ingress Tool Transfer
Tools & malware (3)
JPIN · Dipsind · adbupd
Reporting (1)
- PLATINUM: Targeted attacks in South and Southeast Asia — Windows Defender Advanced Threat Hunting Team