Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors PLATINUM

Also known as: TwoForOne, DeadlyKiss, South East Asia, Singapore, G0068, ATK33

Description

PLATINUM is an activity group that has targeted victims since at least 2009. The group has focused on targets associated with governments and related organizations in South and Southeast Asia. (Citation: Microsoft PLATINUM April 2016)

TTP Summary

Hellsing

Goals & Targeting

Targeted Sectors

Government
Defense
Telecommunications

Targeted Countries / Regions

southeast_asia

AI Analysis

· 1 week ago

Executive Summary

PLATINUM, also known as TwoForOne or DeadlyKiss, is a long-active cyber threat actor primarily involved in espionage activities targeting government, defense, and telecommunications sectors in Southeast Asia since at least 2016. Known for their use of sophisticated tactics including spear-phishing and credential harvesting, PLATINUM has demonstrated persistence and technical proficiency in compromising high-value targets.

Goals & Targeting

PLATINUM's primary strategic objective appears to be espionage, with a focus on collecting sensitive information from government and defense sectors in Southeast Asia. Their targeting of telecommunications companies may indicate an interest in surveillance capabilities or strategic infrastructure. The group's sustained activity over years suggests a long-term commitment to gathering intelligence for either diplomatic or military advantage, possibly in support of a nation-state agenda. victims are typically high-value targets within critical national infrastructure sectors.

Enhanced Description

PLATINUM is an advanced persistent threat (APT) group that has been active in the cyber espionage landscape since at least 2016. The group has primarily targeted government entities, defense organizations, and telecommunications companies across Southeast Asia, with a particular focus on Singapore and nearby regions. Despite their elusive nature, PLATINUM is known to employ a range ofTTPs (tactics, techniques, and procedures) including spear-phishing campaigns, malware deployment, and lateral movement within networks. The group's activities are characterized by a focus on data exfiltration and intelligence gathering, often leveraging custom tools and tailored attacks to achieve their objectives. While the exact origins of PLATINUM remain unclear, their consistent targeting of regional governments suggests a possible state-sponsored or state-aligned motivation.

Key Capabilities

  • Spear-phishing attacks using malicious Office documents
  • Credential harvesting via keylogging and API hooking
  • Process injection for malware persistence
  • Use of custom tools like adbupd and JPIN
  • Ingress tool transfer for lateral movement

MITRE ATT&CK Tactics

Collection
Exfiltration
Lateral Movement
Defense Evasion
Credential Access
Discovery

ATT&CK Techniques

T1056.001: Keylogging
T1204.002: Malicious File
T1036: Masquerading
T1055: Process Injection
T1003.001: LSASS Memory
T1068: Exploitation for Privilege Escalation
T1056.004: Credential API Hooking
T1566.001: Spearphishing Attachment
T1095: Non-Application Layer Protocol
T1189: Drive-by Compromise
T1105: Ingress Tool Transfer

Software / Tooling

Hellsing
adbupd
JPIN
Dipsind

Campaigns & Victims

PLATINUM's campaigns are characterized by a prolonged period of activity and a focus on maintaining persistence within targeted networks. The group is known to deploy custom tools like adbupd and JPIN, which suggest a high level of technical proficiency. Their use of Spearphishing Attachment (T1566.001) indicates an initial access vector through malicious emails with attachments. Campaigns have been observed targeting Southeast Asian governments, defense contractors, and telecommunications firms. Notable past operations include the Hellsing campaign, which utilized a range of TTPs including keylogging and credential harvesting.

IOC Patterns

  • Spearphishing campaigns using malicious Office documents
  • Malicious processes leveraging process injection techniques
  • Use of custom tools like adbupd and JPIN
  • Network traffic indicative of C2 communication over non-standard protocols

Recommended Actions

  • Implement strict email filtering to detect and block spear-phishing attempts
  • Monitor for unusual process activity indicating potential process injection attacks
  • Conduct regular network monitoring for known malicious file hashes associated with PLATINUM campaigns
  • Enforce least privilege principles to mitigate the risk of lateral movement within networks

Suggested Tags

APT
espionage
government
defense
Southeast Asia
cyber-espionage

Confidence Assessment

There is a high confidence in PLATINUM's primary motivation as espionage and targeting sectors due to multiple intelligence sources and consistent TTPs observed over the years. However, specific technical details about their tools and exact campaign timelines remain limited, which introduces some uncertainty in attributing certain attacks definitively to this group.

ATT&CK Techniques

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Microsoft PLATINUM April 2016 — Windows Defender Advanced Threat Hunting Team. (2016, April 29). PLATINUM: Targeted attacks in South and Southeast Asia. Retrieved February 15, 2018.

Intel Summary

11

Techniques

6

Tools

1

Campaigns

0

IOCs

0

Observed Data

7

Tactics

Tags

APT
Government Targeting
espionage
government
defense
Southeast Asia
cyber-espionage

Details

MITRE ID
G0068
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--f9c06633-dcff-48a1-8588-759e7cec5694
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.