Threat group.View on attack.mitre.org
Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China, Japan, Russia, Poland, and other nations. Higaisa was first disclosed in early 2019 but is assessed to have operated as early as 2009.
| Technique | Procedure example |
|---|---|
| T1001.003 Protocol or Service Impersonation |
Higaisa used a FakeTLS session for C2 communications. |
| T1016 System Network Configuration Discovery |
Higaisa used |
| T1027.001 Binary Padding |
Higaisa performed padding with null bytes before calculating its hash. |
| T1027.013 Encrypted/Encoded File |
Higaisa used Base64 encoded compressed payloads. |
| T1027.015 Compression |
Higaisa used Base64 encoded compressed payloads. |
| T1029 Scheduled Transfer |
Higaisa sent the victim computer identifier in a User-Agent string back to the C2 server every 10 minutes. |
| T1036.004 Masquerade Task or Service |
Higaisa named a shellcode loader binary |
| T1041 Exfiltration Over C2 Channel |
Higaisa exfiltrated data over its C2 channel. |
| T1053.005 Scheduled Task |
Higaisa dropped and added |
| T1057 Process Discovery |
Higaisa’s shellcode attempted to find the process ID of the current process. |
| T1059.003 Windows Command Shell |
Higaisa used |
| T1059.005 Visual Basic |
Higaisa has used VBScript code on the victim's machine. |
| T1059.007 JavaScript |
Higaisa used JavaScript to execute additional files. |
| T1071.001 Web Protocols |
Higaisa used HTTP and HTTPS to send data back to its C2 server. |
| T1082 System Information Discovery |
Higaisa collected the system GUID and computer name. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.