ATT&CKReferencesZscaler Higaisa 2020

Zscaler Higaisa 2020

Singh, S. Singh, A. (2020, June 11). The Return on the Higaisa APT. Retrieved March 2, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
GroupHigaisa

Higaisa used a FakeTLS session for C2 communications.

T1016
System Network Configuration Discovery
GroupHigaisa

Higaisa used ipconfig to gather network configuration information.

T1027.001
Binary Padding
GroupHigaisa

Higaisa performed padding with null bytes before calculating its hash.

T1027.013
Encrypted/Encoded File
GroupHigaisa

Higaisa used Base64 encoded compressed payloads.

T1027.015
Compression
GroupHigaisa

Higaisa used Base64 encoded compressed payloads.

T1036.004
Masquerade Task or Service
GroupHigaisa

Higaisa named a shellcode loader binary svchast.exe to spoof the legitimate svchost.exe.

T1041
Exfiltration Over C2 Channel
GroupHigaisa

Higaisa exfiltrated data over its C2 channel.

T1053.005
Scheduled Task
GroupHigaisa

Higaisa dropped and added officeupdate.exe to scheduled tasks.

T1057
Process Discovery
GroupHigaisa

Higaisa’s shellcode attempted to find the process ID of the current process.

T1059.003
Windows Command Shell
GroupHigaisa

Higaisa used cmd.exe for execution.

T1059.007
JavaScript
GroupHigaisa

Higaisa used JavaScript to execute additional files.

T1071.001
Web Protocols
GroupHigaisa

Higaisa used HTTP and HTTPS to send data back to its C2 server.

T1090.001
Internal Proxy
GroupHigaisa

Higaisa discovered system proxy settings and used them if available.

T1106
Native API
GroupHigaisa

Higaisa has called various native OS APIs.

T1124
System Time Discovery
GroupHigaisa

Higaisa used a function to gather the current time.

T1140
Deobfuscate/Decode Files or Information
GroupHigaisa

Higaisa used certutil to decode Base64 binaries at runtime and a 16-byte XOR key to decrypt data.

T1204.002
Malicious File
GroupHigaisa

Higaisa used malicious e-mail attachments to lure victims into executing LNK files.

T1547.001
Registry Run Keys / Startup Folder
GroupHigaisa

Higaisa added a spoofed binary to the start-up folder for persistence.

T1566.001
Spearphishing Attachment
GroupHigaisa

Higaisa has sent spearphishing emails containing malicious attachments.

T1573.001
Symmetric Cryptography
GroupHigaisa

Higaisa used AES-128 to encrypt C2 traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.