PT ESC Threat Intelligence. (2020, June 4). COVID-19 and New Year greetings: an investigation into the tools and methods used by the Higaisa group. Retrieved March 2, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1029 Scheduled Transfer |
GroupHigaisa | Higaisa sent the victim computer identifier in a User-Agent string back to the C2 server every 10 minutes. |
| T1059.003 Windows Command Shell |
GroupHigaisa | Higaisa used |
| T1059.005 Visual Basic |
GroupHigaisa | Higaisa has used VBScript code on the victim's machine. |
| T1059.007 JavaScript |
GroupHigaisa | Higaisa used JavaScript to execute additional files. |
| T1082 System Information Discovery |
GroupHigaisa | Higaisa collected the system GUID and computer name. |
| T1203 Exploitation for Client Execution |
GroupHigaisa | Higaisa has exploited CVE-2018-0798 for execution. |
| T1220 XSL Script Processing |
GroupHigaisa | Higaisa used an XSL file to run VBScript code. |
| T1564.003 Hidden Window |
GroupHigaisa | Higaisa used a payload that creates a hidden window. |
| T1574.001 DLL |
GroupHigaisa | Higaisa’s JavaScript file used a legitimate Microsoft Office 2007 package to side-load the |
| T1680 Local Storage Discovery |
GroupHigaisa | Higaisa collected the system volume serial number. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.