Singh, S. Singh, A. (2020, June 11). The Return on the Higaisa APT. Retrieved March 2, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
GroupHigaisa | Higaisa used a FakeTLS session for C2 communications. |
| T1016 System Network Configuration Discovery |
GroupHigaisa | Higaisa used |
| T1027.001 Binary Padding |
GroupHigaisa | Higaisa performed padding with null bytes before calculating its hash. |
| T1027.013 Encrypted/Encoded File |
GroupHigaisa | Higaisa used Base64 encoded compressed payloads. |
| T1027.015 Compression |
GroupHigaisa | Higaisa used Base64 encoded compressed payloads. |
| T1036.004 Masquerade Task or Service |
GroupHigaisa | Higaisa named a shellcode loader binary |
| T1041 Exfiltration Over C2 Channel |
GroupHigaisa | Higaisa exfiltrated data over its C2 channel. |
| T1053.005 Scheduled Task |
GroupHigaisa | Higaisa dropped and added |
| T1057 Process Discovery |
GroupHigaisa | Higaisa’s shellcode attempted to find the process ID of the current process. |
| T1059.003 Windows Command Shell |
GroupHigaisa | Higaisa used |
| T1059.007 JavaScript |
GroupHigaisa | Higaisa used JavaScript to execute additional files. |
| T1071.001 Web Protocols |
GroupHigaisa | Higaisa used HTTP and HTTPS to send data back to its C2 server. |
| T1090.001 Internal Proxy |
GroupHigaisa | Higaisa discovered system proxy settings and used them if available. |
| T1106 Native API |
GroupHigaisa | Higaisa has called various native OS APIs. |
| T1124 System Time Discovery |
GroupHigaisa | Higaisa used a function to gather the current time. |
| T1140 Deobfuscate/Decode Files or Information |
GroupHigaisa | Higaisa used certutil to decode Base64 binaries at runtime and a 16-byte XOR key to decrypt data. |
| T1204.002 Malicious File |
GroupHigaisa | Higaisa used malicious e-mail attachments to lure victims into executing LNK files. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupHigaisa | Higaisa added a spoofed binary to the start-up folder for persistence. |
| T1566.001 Spearphishing Attachment |
GroupHigaisa | Higaisa has sent spearphishing emails containing malicious attachments. |
| T1573.001 Symmetric Cryptography |
GroupHigaisa | Higaisa used AES-128 to encrypt C2 traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.