PLATINUM

MITRE ATT&CK: G0068 View on attack.mitre.org

Aliases: TwoForOne, ATK33, PLATINUM

First seen
2009-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-06-15 10:45:04
Profile updated
2026-07-07 12:33:58

Targeted industries: government-and-public-sector

Targeted regions: country_code:in country_code:pk country_code:bd

Context

PLATINUM is an activity group that has targeted victims since at least 2009. The group has focused on targets associated with governments and related organizations in South and Southeast Asia.

Detection coverage

  • 276 Sigma rules

Malware & tools used

  • Drive-by Compromise (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Malicious File (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Credential API Hooking (attack-pattern)
  • Keylogging (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Process Injection (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Masquerading (attack-pattern)
  • adbupd (malware)
  • JPIN (malware)
  • Dipsind (malware)

Reports & references

  • Microsoft — Platinum%20Feature%20Article%20 %20Targeted%20Attacks%20In%20South%20And%20Southeast%20Asia%20April%202016 (report)
  • Microsoft — Digging Deep For Platinum (report)
  • MITRE ATT&CK — G0068 (report)
  • Microsoft — Platinum%20Feature%20Article%20 %20Targeted%20Attacks%20In%20South%20And%20Southeast%20Asia%20April%202016 (report)

External references