ATT&CKReferencesPTSecurity Higaisa 2020

PTSecurity Higaisa 2020

PT ESC Threat Intelligence. (2020, June 4). COVID-19 and New Year greetings: an investigation into the tools and methods used by the Higaisa group. Retrieved March 2, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1029
Scheduled Transfer
GroupHigaisa

Higaisa sent the victim computer identifier in a User-Agent string back to the C2 server every 10 minutes.

T1059.003
Windows Command Shell
GroupHigaisa

Higaisa used cmd.exe for execution.

T1059.005
Visual Basic
GroupHigaisa

Higaisa has used VBScript code on the victim's machine.

T1059.007
JavaScript
GroupHigaisa

Higaisa used JavaScript to execute additional files.

T1082
System Information Discovery
GroupHigaisa

Higaisa collected the system GUID and computer name.

T1203
Exploitation for Client Execution
GroupHigaisa

Higaisa has exploited CVE-2018-0798 for execution.

T1220
XSL Script Processing
GroupHigaisa

Higaisa used an XSL file to run VBScript code.

T1564.003
Hidden Window
GroupHigaisa

Higaisa used a payload that creates a hidden window.

T1574.001
DLL
GroupHigaisa

Higaisa’s JavaScript file used a legitimate Microsoft Office 2007 package to side-load the OINFO12.OCX dynamic link library.

T1680
Local Storage Discovery
GroupHigaisa

Higaisa collected the system volume serial number.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.