PLATINUM
MITRE ATT&CK: G0068 View on attack.mitre.org
Aliases: TwoForOne, ATK33, PLATINUM
- First seen
- 2009-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Last IoC activity
- 2026-06-15 10:45:04
- Profile updated
- 2026-07-07 12:33:58
Targeted industries: government-and-public-sector
Targeted regions: country_code:in country_code:pk country_code:bd
Context
PLATINUM is an activity group that has targeted victims since at least 2009. The group has focused on targets associated with governments and related organizations in South and Southeast Asia.
Detection coverage
- 276 Sigma rules
Malware & tools used
- Drive-by Compromise (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Malicious File (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Credential API Hooking (attack-pattern)
- Keylogging (attack-pattern)
- LSASS Memory (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Process Injection (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Masquerading (attack-pattern)
- adbupd (malware)
- JPIN (malware)
- Dipsind (malware)
Reports & references
- Microsoft — Platinum%20Feature%20Article%20 %20Targeted%20Attacks%20In%20South%20And%20Southeast%20Asia%20April%202016 (report)
- Microsoft — Digging Deep For Platinum (report)
- MITRE ATT&CK — G0068 (report)
- Microsoft — Platinum%20Feature%20Article%20 %20Targeted%20Attacks%20In%20South%20And%20Southeast%20Asia%20April%202016 (report)