Malwarebytes Threat Intelligence Team. (2020, June 4). New LNK attack tied to Higaisa APT discovered. Retrieved March 2, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupHigaisa | Higaisa used |
| T1027.013 Encrypted/Encoded File |
GroupHigaisa | Higaisa used Base64 encoded compressed payloads. |
| T1027.015 Compression |
GroupHigaisa | Higaisa used Base64 encoded compressed payloads. |
| T1036.004 Masquerade Task or Service |
GroupHigaisa | Higaisa named a shellcode loader binary |
| T1053.005 Scheduled Task |
GroupHigaisa | Higaisa dropped and added |
| T1059.003 Windows Command Shell |
GroupHigaisa | Higaisa used |
| T1059.007 JavaScript |
GroupHigaisa | Higaisa used JavaScript to execute additional files. |
| T1071.001 Web Protocols |
GroupHigaisa | Higaisa used HTTP and HTTPS to send data back to its C2 server. |
| T1082 System Information Discovery |
GroupHigaisa | Higaisa collected the system GUID and computer name. |
| T1140 Deobfuscate/Decode Files or Information |
GroupHigaisa | Higaisa used certutil to decode Base64 binaries at runtime and a 16-byte XOR key to decrypt data. |
| T1204.002 Malicious File |
GroupHigaisa | Higaisa used malicious e-mail attachments to lure victims into executing LNK files. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupHigaisa | Higaisa added a spoofed binary to the start-up folder for persistence. |
| T1566.001 Spearphishing Attachment |
GroupHigaisa | Higaisa has sent spearphishing emails containing malicious attachments. |
| T1680 Local Storage Discovery |
GroupHigaisa | Higaisa collected the system volume serial number. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.