PLATINUM is a long-running cyber espionage threat actor known for targeting organizations in Asia, particularly government and related entities in Southeast Asia. The group is also tracked as Fallow Squall, Gingersnap, Parasite, Rubyvine, and TwoForOne. It is notable for combining conventional spearphishing-based intrusion methods with unusual tradecraft involving Intel Active Management Technology (AMT) Serial-over-LAN to move files and conceal command-and-control activity below the operating system layer, reducing visibility to host-based security controls. PLATINUM has used spearphishing emails with malicious attachments as a primary initial access vector and has relied on user execution to trigger compromise. The group has also been linked to targeted exploitation, including use of CVE-2015-2545 for code execution in Microsoft Office and CVE-2015-2546 for privilege escalation to SYSTEM. Reported post-compromise behavior includes keylogging, process injection, and privilege-escalation activity. Its tradecraft emphasizes stealth, including masquerading and abuse of lower-level platform capabilities to evade detection. The actor is assessed as espionage-motivated based on its targeted operations and operational style rather than financially motivated or disruptive ransomware activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
Let’s take a look at the vulnerability CVE-2015-2545 and its extension CVE-2015-2546. Microsoft Office versions 2007 SP3, 2010 SP2, 2013 SP1 and 2013 RT SP1 are exposed to the former – it allows remote attackers to execute arbitrary code using a crafted EPS file.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
The latter allows remote attackers to execute arbitrary code in kernel mode. Both vulnerabilities were used in a targeted attack by the Platinum (aka TwoForOne) group. The attackers first exploited CVE-2015-2545 to execute code in the process WINWORD.EXE, and then CVE-2015-2546 to escalate privileges up to the SYSTEM level. CVE-2015-2546 is a classic Use-After-Free (UAF)-type vulnerability.
The following analytic detects when su runs from a page-cache-corrupted binary... This activity is significant because it indicates a possible privilege escalation attempt, allowing a user to gain root access... CVE CVE-2026-31431 ... References ... copy-fail-CVE-2026-31431
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with the generic installation exploitation analytic, but no campaign-specific activity is described in this reference.
Mentioned only as an annotation/tag associated with a privilege escalation detection.
Mentioned only as an annotated threat actor associated with the detection content; no campaign or activity by the group is described in this reference.
Mentioned only as one of many threat actors associated with the ATT&CK technique Exploitation for Privilege Escalation in a detection annotation; no campaign or activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.