Also known as: TwoForOne, DeadlyKiss, South East Asia, Singapore, G0068, ATK33
PLATINUM is an activity group that has targeted victims since at least 2009. The group has focused on targets associated with governments and related organizations in South and Southeast Asia. (Citation: Microsoft PLATINUM April 2016)
Hellsing
Targeted Sectors
Targeted Countries / Regions
Executive Summary
PLATINUM, also known as TwoForOne or DeadlyKiss, is a long-active cyber threat actor primarily involved in espionage activities targeting government, defense, and telecommunications sectors in Southeast Asia since at least 2016. Known for their use of sophisticated tactics including spear-phishing and credential harvesting, PLATINUM has demonstrated persistence and technical proficiency in compromising high-value targets.
Goals & Targeting
PLATINUM's primary strategic objective appears to be espionage, with a focus on collecting sensitive information from government and defense sectors in Southeast Asia. Their targeting of telecommunications companies may indicate an interest in surveillance capabilities or strategic infrastructure. The group's sustained activity over years suggests a long-term commitment to gathering intelligence for either diplomatic or military advantage, possibly in support of a nation-state agenda. victims are typically high-value targets within critical national infrastructure sectors.
Enhanced Description
PLATINUM is an advanced persistent threat (APT) group that has been active in the cyber espionage landscape since at least 2016. The group has primarily targeted government entities, defense organizations, and telecommunications companies across Southeast Asia, with a particular focus on Singapore and nearby regions. Despite their elusive nature, PLATINUM is known to employ a range ofTTPs (tactics, techniques, and procedures) including spear-phishing campaigns, malware deployment, and lateral movement within networks. The group's activities are characterized by a focus on data exfiltration and intelligence gathering, often leveraging custom tools and tailored attacks to achieve their objectives. While the exact origins of PLATINUM remain unclear, their consistent targeting of regional governments suggests a possible state-sponsored or state-aligned motivation.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
PLATINUM's campaigns are characterized by a prolonged period of activity and a focus on maintaining persistence within targeted networks. The group is known to deploy custom tools like adbupd and JPIN, which suggest a high level of technical proficiency. Their use of Spearphishing Attachment (T1566.001) indicates an initial access vector through malicious emails with attachments. Campaigns have been observed targeting Southeast Asian governments, defense contractors, and telecommunications firms. Notable past operations include the Hellsing campaign, which utilized a range of TTPs including keylogging and credential harvesting.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
There is a high confidence in PLATINUM's primary motivation as espionage and targeting sectors due to multiple intelligence sources and consistent TTPs observed over the years. However, specific technical details about their tools and exact campaign timelines remain limited, which introduces some uncertainty in attributing certain attacks definitively to this group.
Hellsing
No observed data linked yet.
No IOCs linked yet.
11
Techniques
6
Tools
1
Campaigns
0
IOCs
0
Observed Data
7
Tactics