Security Experts:

Connect with us

Hi, what are you looking for?



“Platinum” Cyberspies Abuse Intel AMT to Evade Detection

The cyber-espionage group tracked by Microsoft as “Platinum” has started abusing a component of Intel’s Active Management Technology (AMT) in attacks aimed at organizations in Southeast Asia.

The cyber-espionage group tracked by Microsoft as “Platinum” has started abusing a component of Intel’s Active Management Technology (AMT) in attacks aimed at organizations in Southeast Asia.

The activities of the Platinum group, which has been active since at least 2009, were exposed just over one year ago by Microsoft. At the time, it had been leveraging a Windows feature called hotpatching in attacks targeting government organizations, intelligence agencies, defense institutes and ISPs in South and Southeast Asia.

Researchers reported at the time that the information stolen by the advanced persistent threat (APT) actor had been used for indirect economic advantages, not direct financial gain.

Microsoft noticed recently that a file transfer tool used by the group had started leveraging Intel AMT’s Serial-over-LAN (SOL) feature.

Previous versions of the tool used regular network APIs to communicate over TCP/IP. A more recent version of the tool started using the AMT SOL feature, most likely in an effort to increase its chances of evading detection.

Intel’s AMT, which is part of the vPro technology offering, allows users to remotely manage a system regardless of its power state and the presence or absence of an operating system. The SOL feature also works all the time, even without the OS, and it provides a virtual serial port. A management console can connect to this port, boot to a basic DOS system, and communicate with software that listens on a designated COM port.

Since SOL works independently of the operating system, communications are not picked up by firewalls and network monitoring applications running on the device.

This makes Platinum’s file transfer tool stealthy and allows it to evade some security products. However, Microsoft pointed out that its Windows Defender Advanced Threat Protection product can identify malicious usage of the SOL feature.

Microsoft has been working with Intel to analyze the file transfer tool and determined that the attackers have not exploited any AMT vulnerabilities, and instead they misused the technology after gaining administrative access to targeted systems.

In order to abuse the SOL feature, an attacker would have to obtain existing credentials if AMT was already provisioned, or they can enable AMT themselves, which allows them to set their own username and password for the SOL session.

While in this case the attackers have not exploited any AMT vulnerabilities, the technology has been known to contain security holes. Intel recently issued a critical alert to warn users of a privilege escalation flaw that had existed for more than nine years.

Related Reading: China-Linked Cyberspies Lure Victims With Security Conference Invites

Related Reading: Winnti Group Uses GitHub for C&C Communications

Related Reading: India-Linked Threat Actor Targets Military, Political Entities Worldwide

Written By

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this webinar to learn best practices that organizations can use to improve both their resilience to new threats and their response times to incidents.


Join this live webinar as we explore the potential security threats that can arise when third parties are granted access to a sensitive data or systems.


Expert Insights

Related Content


The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.


WASHINGTON - Cyberattacks are the most serious threat facing the United States, even more so than terrorism, according to American defense experts. Almost half...


No one combatting cybercrime knows everything, but everyone in the battle has some intelligence to contribute to the larger knowledge base.


A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...


Websites of German airports, administration bodies and banks were hit by DDoS attacks attributed to Russian hacker group Killnet

Malware & Threats

Threat actors are increasingly abusing Microsoft OneNote documents to deliver malware in both targeted and spray-and-pray campaigns.


Iranian APT Moses Staff is leaking data stolen from Saudi Arabia government ministries under the recently created Abraham's Ax persona


The war in Ukraine is the first major conflagration between two technologically advanced powers in the age of cyber. It prompts us to question...