Higaisa

G0126

Threat group.View on attack.mitre.org

About this group

Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China, Japan, Russia, Poland, and other nations. Higaisa was first disclosed in early 2019 but is assessed to have operated as early as 2009.

Techniques used28

Procedure examples28

TechniqueProcedure example
T1001.003
Protocol or Service Impersonation

Higaisa used a FakeTLS session for C2 communications.

T1016
System Network Configuration Discovery

Higaisa used ipconfig to gather network configuration information.

T1027.001
Binary Padding

Higaisa performed padding with null bytes before calculating its hash.

T1027.013
Encrypted/Encoded File

Higaisa used Base64 encoded compressed payloads.

T1027.015
Compression

Higaisa used Base64 encoded compressed payloads.

T1029
Scheduled Transfer

Higaisa sent the victim computer identifier in a User-Agent string back to the C2 server every 10 minutes.

T1036.004
Masquerade Task or Service

Higaisa named a shellcode loader binary svchast.exe to spoof the legitimate svchost.exe.

T1041
Exfiltration Over C2 Channel

Higaisa exfiltrated data over its C2 channel.

T1053.005
Scheduled Task

Higaisa dropped and added officeupdate.exe to scheduled tasks.

T1057
Process Discovery

Higaisa’s shellcode attempted to find the process ID of the current process.

T1059.003
Windows Command Shell

Higaisa used cmd.exe for execution.

T1059.005
Visual Basic

Higaisa has used VBScript code on the victim's machine.

T1059.007
JavaScript

Higaisa used JavaScript to execute additional files.

T1071.001
Web Protocols

Higaisa used HTTP and HTTPS to send data back to its C2 server.

T1082
System Information Discovery

Higaisa collected the system GUID and computer name.

View all 28 procedure examples

Software3

Campaigns0

None recorded.

References3

  1. Malwarebytes Higaisa 2020 Open source
    Malwarebytes Threat Intelligence Team. (2020, June 4). New LNK attack tied to Higaisa APT discovered. Retrieved March 2, 2021.
  2. PTSecurity Higaisa 2020 Open source
    PT ESC Threat Intelligence. (2020, June 4). COVID-19 and New Year greetings: an investigation into the tools and methods used by the Higaisa group. Retrieved March 2, 2021.
  3. Zscaler Higaisa 2020 Open source
    Singh, S. Singh, A. (2020, June 11). The Return on the Higaisa APT. Retrieved March 2, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.