logo

PLATINUM__2019__Titanium_the_Platinum_group_strikes_again.pdf

ID: fff84b32-da84-4e49-ba83-9ea24495d858

STIX ID: report--fff84b32-da84-4e49-ba83-9ea24495d858

Threat Score

80/100

Uploaded: 2026-08-19

Published Date: 2019-11-11

Last Modified Date: 2019-11-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Securelist analysis describes 'Titanium', a sophisticated multi-stage Trojan-backdoor used by the Platinum APT against targets in South and Southeast Asia. The attack chain includes SYSTEM-capable exploits or shellcode injection, encrypted password-protected SFX archives, COM/Service loader DLLs, a BITS-based downloader, scheduled-task persistence using a bundled cURL DLL and PowerShell scripts, and a backdoor that communicates with C2 via AES-encrypted, steganographically-embedded data in PNGs; the report provides configuration details, commands supported by the backdoor, and IoCs such as the C2 host 70.39.115.196.