The secretive Platinum group — hackers known for advanced tools and thought to be state sponsored — has resurfaced, according to Kaspersky.

Why it matters: Platinum is a formidable group. When Microsoft first profiled them in 2016, it was for malware that the group had used undetected for at least seven years — an eternity in hacker time and evidence of how talented the group is.

  • The Kaspersky discovery, too, has been used for at least seven years.

Background: Little is known about Platinum. What is known is pretty formidable.

  • Platinum burst on to the scene with malware taking advantage of Windows "hotfixing," a feature that allowed computers to be updated without rebooting. That malware used four previously unseen security bugs. Most malware don't use any due to the extremely high cost for each one.
  • In 2017, Platinum hackers took advantage of Intel's management engine, a second processor in Intel CPUs intended to be used by network administrators.

Details: The new Platinum discovery also has some unique features, especially in how the command-and-control server sent commands to the malware hidden in the HTML code of a website that appeared to be a domain for sale.

  • HTML ignores tabs and spaces in the code. It also ignores the order of certain formatting commands. For example, if you say text should be at the center of a page and colored white, it is the same as saying text should be white and at the center of a page.
  • Commands were encoded into the webpage in the form of ordered commands, spaces and tabs.
  • Kaspersky notes in a press release that would make commands "almost impossible" to detect in network traffic.

Victims: Kaspersky caught the new malware targeting south and southeast Asian "diplomatic, government and military entities." That's in line with what Microsoft reported in 2016.

Go deeper

Trump agrees to TikTok deal "in concept"

Illustration: Sarah Grillo/Axios

President Trump on Saturday said he approved "in concept" a deal whereby TikTok will be allowed to continue operating in the U.S., with Oracle as its "trusted technology partner."

Why it matters: TikTok has nearly 100 million U.S. users, and is still growing fast. Trump has threatened to ban it, due to data privacy concerns related to TikTok's ownership by Chinese tech company

Updated 55 mins ago - Politics & Policy

Coronavirus dashboard

Illustration: Sarah Grillo/Axios

  1. Global: Total confirmed cases as of 6:15 p.m. ET: 30,611,684 — Total deaths: 953,820— Total recoveries: 20,836,867Map.
  2. U.S.: Total confirmed cases as of 6:15 p.m. ET: 6,756,781 — Total deaths: 199,090 — Total recoveries: 2,556,465 — Total tests: 93,150,052Map.
  3. Politics: In reversal, CDC again recommends coronavirus testing for asymptomatic people.
  4. Health: The dwindling chances of eliminating COVID-19.
  5. World: Guatemalan president tests positive for COVID-19 — The countries painting their pandemic recoveries green.

Trump says he expects to announce a Supreme Court nominee "next week"

President Trump speaking prior to his departure from the White House on Sept. 19. Photo: Sarah Silbiger/Getty Images

President Trump said Saturday he expects to announce a nominee for Justice Ruth Bader Ginsburg's vacant Supreme Court seat “next week” and that the person will “most likely" be a woman.

What he's saying: "If somebody were to ask me now, I would say that a woman would be in first place, yes. The choice of a woman, I would say, would certainly be appropriate," the president told pool reporters.