Higaisa
Overview
Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China, Japan, Russia, Poland, and other nations. Higaisa was first disclosed in early 2019 but is assessed to have operated as early as 2009.
Naming & attribution
Higaisa is tracked under 1 names across the industry. It uses 28 documented ATT&CK techniques — more than 62% of the 174 groups tracked here.
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1029Scheduled Transfer — used by 1 of 174 groups -
T1220XSL Script Processing — used by 2 of 174 groups -
T1001.003Protocol or Service Impersonation — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Darkhotel South Korea — 12 shared techniques (30% overlap)
- Sidewinder India — 13 shared techniques (29% overlap)
- Tropic Trooper China — 14 shared techniques (26% overlap)
- APT19 China — 10 shared techniques (26% overlap)
- Molerats — 9 shared techniques (26% overlap)
- Inception Russia — 10 shared techniques (25% overlap)
Targets
Government
Regions
China · Japan · Nepal · North Korea · Poland · Russia · Singapore · Switzerland
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1203
TTPs — 28 techniques across 7 tactics
Initial Access
-
T1566.001Spearphishing Attachment
Execution
-
T1053.005Scheduled Task -
T1059.003Windows Command Shell -
T1059.005Visual Basic -
T1059.007JavaScript -
T1106Native API -
T1203Exploitation for Client Execution -
T1204.002Malicious File
Persistence
-
T1547.001Registry Run Keys / Startup Folder
Stealth
-
T1027.001Binary Padding -
T1027.013Encrypted/Encoded File -
T1027.015Compression -
T1036.004Masquerade Task or Service -
T1140Deobfuscate/Decode Files or Information -
T1220XSL Script Processing -
T1564.003Hidden Window -
T1574.001DLL
Discovery
-
T1016System Network Configuration Discovery -
T1057Process Discovery -
T1082System Information Discovery -
T1124System Time Discovery -
T1680Local Storage Discovery
Command and Control
-
T1001.003Protocol or Service Impersonation -
T1071.001Web Protocols -
T1090.001Internal Proxy -
T1573.001Symmetric Cryptography
Exfiltration
-
T1029Scheduled Transfer -
T1041Exfiltration Over C2 Channel
Tools & malware (3)
PlugX · certutil · gh0st RAT
Reporting (3)
- The Return on the Higaisa APT — Singh, S. Singh, A
- New LNK attack tied to Higaisa APT discovered — Malwarebytes Threat Intelligence Team
- COVID-19 and New Year greetings: an investigation into the tools and methods used by the Higaisa group — PT ESC Threat Intelligence