ATT&CKReferencesMalwarebytes Higaisa 2020

Malwarebytes Higaisa 2020

Malwarebytes Threat Intelligence Team. (2020, June 4). New LNK attack tied to Higaisa APT discovered. Retrieved March 2, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupHigaisa

Higaisa used ipconfig to gather network configuration information.

T1027.013
Encrypted/Encoded File
GroupHigaisa

Higaisa used Base64 encoded compressed payloads.

T1027.015
Compression
GroupHigaisa

Higaisa used Base64 encoded compressed payloads.

T1036.004
Masquerade Task or Service
GroupHigaisa

Higaisa named a shellcode loader binary svchast.exe to spoof the legitimate svchost.exe.

T1053.005
Scheduled Task
GroupHigaisa

Higaisa dropped and added officeupdate.exe to scheduled tasks.

T1059.003
Windows Command Shell
GroupHigaisa

Higaisa used cmd.exe for execution.

T1059.007
JavaScript
GroupHigaisa

Higaisa used JavaScript to execute additional files.

T1071.001
Web Protocols
GroupHigaisa

Higaisa used HTTP and HTTPS to send data back to its C2 server.

T1082
System Information Discovery
GroupHigaisa

Higaisa collected the system GUID and computer name.

T1140
Deobfuscate/Decode Files or Information
GroupHigaisa

Higaisa used certutil to decode Base64 binaries at runtime and a 16-byte XOR key to decrypt data.

T1204.002
Malicious File
GroupHigaisa

Higaisa used malicious e-mail attachments to lure victims into executing LNK files.

T1547.001
Registry Run Keys / Startup Folder
GroupHigaisa

Higaisa added a spoofed binary to the start-up folder for persistence.

T1566.001
Spearphishing Attachment
GroupHigaisa

Higaisa has sent spearphishing emails containing malicious attachments.

T1680
Local Storage Discovery
GroupHigaisa

Higaisa collected the system volume serial number.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.