PLATINUM is a long-running cyber-espionage threat actor assessed as a sophisticated, well-resourced nation-state operation. The group has been active since at least 2009 and is primarily associated with espionage targeting organizations and government entities in South and Southeast Asia, including government agencies, defense organizations, and telecommunications or ISP-related targets. Common aliases include Fallow Squall, Gingersnap, Parasite, Rubyvine, and PLATINUM. PLATINUM is known for stealth-focused tradecraft, custom malware development, and selective use of advanced post-compromise techniques. The group has used spearphishing emails with malicious attachments as a primary initial access vector and has also relied on exploit-driven, multi-stage intrusion chains. Reported tooling and operations include custom backdoors, keyloggers, data stealers, shellcode loaders, downloaders, and the Titanium backdoor. In Titanium-related activity, the group employed layered execution chains involving shellcode, encrypted payloads, wrapper DLLs, PowerShell, scheduled tasks, COM hijacking, Windows service installation, BITS, and WMI. The final backdoor supported command execution, file theft and deployment, configuration updates, and interactive operator control, while using encrypted communications and steganographic concealment of tasking data. A defining characteristic of PLATINUM is its emphasis on evasion and covert persistence. The group has used process injection, including hot patching, to modify running processes and cloak malicious code. It has also been linked to exploitation for privilege escalation and related post-exploitation behaviors. Microsoft publicly documented PLATINUM’s abuse of Intel Active Management Technology Serial-over-LAN as a covert file-transfer channel, allowing communications to bypass the host operating system’s normal networking stack and many host-based security controls. That activity did not rely on an Intel vulnerability; rather, it abused legitimate remote-management functionality after compromise and administrative access had been obtained. PLATINUM is widely regarded as one of the more technically advanced espionage actors operating in the Asia-Pacific region. Its operations demonstrate careful staging, strong operational security, extensive use of legitimate system components, and a preference for low-visibility collection and exfiltration methods over disruptive effects.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
CVE-2015-2545 is a vulnerability discovered in 2015 and corrected with Microsoft’s update MS15-099... enables an attacker to execute arbitrary code using a specially crafted EPS image file... exploited in the wild in August 2015... used in targeted attack by the Platinum group.
The following analytic detects when su runs from a page-cache-corrupted binary... This activity is significant because it indicates a possible privilege escalation attempt, allowing a user to gain root access... CVE CVE-2026-31431 ... References ... copy-fail-CVE-2026-31431
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an annotated threat actor associated with the ATT&CK technique Process Injection (T1055) in a Splunk detection entry; no campaign or activity is described.
Mentioned only as an annotation/tag associated with the ATT&CK technique Process Injection (T1055); no campaign or activity by this group is described in the content.
Mentioned only in an annotation/list associated with the detection content; no actor-specific activity is described in this reference.
Mentioned only in the detection annotation metadata; no campaign activity or actor-specific behavior is described in this content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.