Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Charlie Kirk shot dead
  • Nepal protests
  • Russia-Poland tension
  • Israeli strikes in Qatar
  • Larry Ellison
  • Apple event
  • Sunjay Kapur inheritance row
fp-logo
Microsoft's cybercriminal hunters track down elusive 'Platinum' hacking group
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • News & Analysis
  • Microsoft's cybercriminal hunters track down elusive 'Platinum' hacking group

Microsoft's cybercriminal hunters track down elusive 'Platinum' hacking group

tech2 News Staff • April 28, 2016, 08:37:18 IST
Whatsapp Facebook Twitter

Microsoft tracks down a group of hackers in southeast and south Asia who used Microsoft’s own OS patching service to compromise computers.

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
Microsoft's cybercriminal hunters track down elusive 'Platinum' hacking group

Microsoft’s Windows Defender Advanced Threat Hunting team, known as hunters, track down elusive hacking groups that initiate large scale attacks against targets. The hunters just posted details of a thrilling investigation on Microsoft’s threat detection and response blog. The hunters had to use both machine learning and human intuition to track down a group that targets government organisations, defense institutes and intelligence agencies in South and South East Asia. The group was codenamed “Platinum” by the hunters, as per their tradition of naming potential threats after elements in the periodic table. Platinum abused Window’s own update delivery mechanism to compromise target computers. The affected machine ran Windows Server 2003. Machines running Windows 10 cannot be exploited in the same way. The update mechanism was known as hotpatching, and that method is now discontinued. Hotpatching is a way of updating the operating system without requiring a restart. Hotpatches can apply updates to DLLs and executables in actively running processes. More interesting than the attack vector was the Sherlock-like investigation by the Hunter team. Windows collects anonymous data from over a billion devices. Carving is a process of cutting down the data into meaningful and targeted chunks for further analysis. This step involves narrowing down the scope of further machine based processing by choosing data from a particular region or particular types of irregularities in files. This carved data was further processed with threat detection analytics, which yielded a set of 31 suspicious looking files. The final step in the investigation was an eagle eyed hunter spotting an unusual header in one of the files. This was a manual part of the process, and that one unusual header revealed the infection vector of hotpatching by Platinum.

Tags
Platinum Microsoft hackers Security Windows Windows Server 2003 Hunter windows 10
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

From governance to tourism, how Gen-Z protests have damaged Nepal

From governance to tourism, how Gen-Z protests have damaged Nepal

Did Russia deliberately send drones into Poland’s airspace?

Did Russia deliberately send drones into Poland’s airspace?

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

From governance to tourism, how Gen-Z protests have damaged Nepal

From governance to tourism, how Gen-Z protests have damaged Nepal

Did Russia deliberately send drones into Poland’s airspace?

Did Russia deliberately send drones into Poland’s airspace?

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV