ATT&CKReferencesMicrosoft PLATINUM April 2016

Microsoft PLATINUM April 2016

Windows Defender Advanced Threat Hunting Team. (2016, April 29). PLATINUM: Targeted attacks in South and Southeast Asia. Retrieved February 15, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software3

Campaigns0

None recorded.

Procedure examples38

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupPLATINUM

PLATINUM has used keyloggers that are also capable of dumping credentials.

T1007
System Service Discovery
MalwareJPIN

JPIN can list running services.

T1012
Query Registry
MalwareJPIN

JPIN can enumerate Registry keys.

T1016
System Network Configuration Discovery
MalwareJPIN

JPIN can obtain network information, including DNS, IP, and proxies.

T1027
Obfuscated Files or Information
MalwareJPIN

A JPIN uses a encrypted and compressed payload that is disguised as a bitmap within the resource section of the installer.

T1029
Scheduled Transfer
MalwareDipsind

Dipsind can be configured to only run during normal working hours, which would make its communications harder to distinguish from normal traffic.

T1033
System Owner/User Discovery
MalwareJPIN

JPIN can obtain the victim user name.

T1055
Process Injection
MalwareJPIN

JPIN can inject content into lsass.exe to load a module.

T1055
Process Injection
GroupPLATINUM

PLATINUM has used various methods of process injection including hot patching.

T1056.001
Keylogging
GroupPLATINUM

PLATINUM has used several different keyloggers.

T1056.001
Keylogging
MalwareJPIN

JPIN contains a custom keylogger.

T1056.004
Credential API Hooking
GroupPLATINUM

PLATINUM is capable of using Windows hook interfaces for information gathering such as credential access.

T1057
Process Discovery
MalwareJPIN

JPIN can list running processes.

T1059.003
Windows Command Shell
Malwareadbupd

adbupd can run a copy of cmd.exe.

T1059.003
Windows Command Shell
MalwareDipsind

Dipsind can spawn remote shells.

T1059.003
Windows Command Shell
MalwareJPIN

JPIN can use the command-line utility cacls.exe to change file permissions.

T1068
Exploitation for Privilege Escalation
GroupPLATINUM

PLATINUM has leveraged a zero-day vulnerability to escalate privileges.

T1069.001
Local Groups
MalwareJPIN

JPIN can obtain the permissions of the victim user.

T1070.004
File Deletion
MalwareJPIN

JPIN's installer/uninstaller component deletes itself if it encounters a version of Windows earlier than Windows XP or identifies security-related processes running.

T1071.001
Web Protocols
MalwareDipsind

Dipsind uses HTTP for C2.

T1071.002
File Transfer Protocols
MalwareJPIN

JPIN can communicate over FTP.

T1071.003
Mail Protocols
MalwareJPIN

JPIN can send email over SMTP.

T1082
System Information Discovery
MalwareJPIN

JPIN can obtain system information such as OS version and disk space.

T1083
File and Directory Discovery
MalwareJPIN

JPIN can enumerate drives and their types. It can also change file permissions using cacls.exe.

T1105
Ingress Tool Transfer
MalwareDipsind

Dipsind can download remote files.

T1105
Ingress Tool Transfer
MalwareJPIN

JPIN can download files and upgrade itself.

T1132.001
Standard Encoding
MalwareDipsind

Dipsind encodes C2 traffic with base64.

T1189
Drive-by Compromise
GroupPLATINUM

PLATINUM has sometimes used drive-by attacks against vulnerable browser plugins.

T1197
BITS Jobs
MalwareJPIN

A JPIN variant downloads the backdoor payload via the BITS service.

T1204.002
Malicious File
GroupPLATINUM

PLATINUM has attempted to get users to open malicious files by sending spearphishing emails with attachments to victims.

T1222.001
Windows Permissions
MalwareJPIN

JPIN can use the command-line utility cacls.exe to change file permissions.

T1518.001
Security Software Discovery
MalwareJPIN

JPIN checks for the presence of certain security-related processes and deletes its installer/uninstaller component if it identifies any of them.

T1546.003
Windows Management Instrumentation Event Subscription
Malwareadbupd

adbupd can use a WMI script to achieve persistence.

T1547.004
Winlogon Helper DLL
MalwareDipsind

A Dipsind variant registers as a Winlogon Event Notify DLL to establish persistence.

T1566.001
Spearphishing Attachment
GroupPLATINUM

PLATINUM has sent spearphishing emails with attachments to victims as its primary initial access vector.

T1573.001
Symmetric Cryptography
MalwareDipsind

Dipsind encrypts C2 data with AES256 in ECB mode.

T1573.002
Asymmetric Cryptography
Malwareadbupd

adbupd contains a copy of the OpenSSL library to encrypt C2 traffic.

T1685
Disable or Modify Tools
MalwareJPIN

JPIN can lower security settings by changing Registry keys.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.