NEW: Group Profiler — instant APT intel lookup. Try it →

Higaisa

G0126 South Korea MITRE ATT&CK →

Overview

Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China, Japan, Russia, Poland, and other nations. Higaisa was first disclosed in early 2019 but is assessed to have operated as early as 2009.

Naming & attribution

Higaisa is tracked under 1 names across the industry. It uses 28 documented ATT&CK techniques — more than 62% of the 174 groups tracked here.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1029 Scheduled Transfer — used by 1 of 174 groups
  • T1220 XSL Script Processing — used by 2 of 174 groups
  • T1001.003 Protocol or Service Impersonation — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Darkhotel South Korea — 12 shared techniques (30% overlap)
  • Sidewinder India — 13 shared techniques (29% overlap)
  • Tropic Trooper China — 14 shared techniques (26% overlap)
  • APT19 China — 10 shared techniques (26% overlap)
  • Molerats — 9 shared techniques (26% overlap)
  • Inception Russia — 10 shared techniques (25% overlap)

Targets

Government

Regions

China · Japan · Nepal · North Korea · Poland · Russia · Singapore · Switzerland

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1203

TTPs — 28 techniques across 7 tactics

Tools & malware (3)

PlugX · certutil · gh0st RAT

Reporting (3)