Overview 15 indicators
Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China, Japan, Russia, Poland, and other nations. Higaisa was first disclosed in early 2019 but is assessed to have operated as early as 2009.
| domain | 13 | G0126-domain.txt |
| ipv4 | 1 | G0126.json |
| url | 1 | G0126.json |
Techniques 28 ATT&CK
Open in ATT&CK Navigator → or download the layer (28 techniques, layer 4.5)
- T1001.003 Protocol or Service Impersonation
- T1016 System Network Configuration Discovery
- T1027.001 Binary Padding
- T1027.013 Encrypted/Encoded File
- T1027.015 Compression
- T1029 Scheduled Transfer
- T1036.004 Masquerade Task or Service
- T1041 Exfiltration Over C2 Channel
- T1053.005 Scheduled Task
- T1057 Process Discovery
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1059.007 JavaScript
- T1071.001 Web Protocols
- T1082 System Information Discovery
- T1090.001 Internal Proxy
- T1106 Native API
- T1124 System Time Discovery
- T1140 Deobfuscate/Decode Files or Information
- T1203 Exploitation for Client Execution
- T1204.002 Malicious File
- T1220 XSL Script Processing
- T1547.001 Registry Run Keys / Startup Folder
- T1564.003 Hidden Window
- T1566.001 Spearphishing Attachment
- T1573.001 Symmetric Cryptography
- T1574.001 DLL
- T1680 Local Storage Discovery
Software 3
Principal sources 11 reports
Ranked by how many of this actor's indicators each report brought in.
- 10x.com/StrikeReadyLabs/status/1825885062186860…
- 10x.com/VirITeXplorer/status/1835667782853140788
- 10x.com/TuringAlex/status/1937442563285508449
- 10tgsoft.it/news/news_archivio.asp?id=1568&lang=eng
- 10github.com/StrikeReady-Inc/samples/blob/main/2024-…
- 10virustotal.com/gui/file/f1d519f43c36e24a89b351f00059a1…
- 10virustotal.com/gui/file/1e6c661d6981c0fa56c011c29536e5…
- 10virustotal.com/gui/file/9b73cd0be50e457d9355b702d8b6df…
Timeline 15 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/StrikeReadyLabs/status/1825885062186860… · x.com/VirITeXplorer/status/1835667782853140788 · x.com/TuringAlex/status/1937442563285508449 · tgsoft.it/news/news_archivio.asp?id=1568&lang=eng · github.com/StrikeReady-Inc/samples/blob/main/2024-… · virustotal.com/gui/file/f1d519f43c36e24a89b351f00059a1… · virustotal.com/gui/file/1e6c661d6981c0fa56c011c29536e5… · virustotal.com/gui/file/9b73cd0be50e457d9355b702d8b6df…
domain xianggang000.oss-cn-hongkong.aliyuncs.com domain yitoo.oss-cn-hongkong.aliyuncs.com url http://152.42.226.161 -
x.com/StrikeReadyLabs/status/1825885062186860… · x.com/VirITeXplorer/status/1835667782853140788 · x.com/TuringAlex/status/1937442563285508449 · tgsoft.it/news/news_archivio.asp?id=1568&lang=eng · github.com/StrikeReady-Inc/samples/blob/main/2024-… · virustotal.com/gui/file/f1d519f43c36e24a89b351f00059a1… · virustotal.com/gui/file/1e6c661d6981c0fa56c011c29536e5… · virustotal.com/gui/file/9b73cd0be50e457d9355b702d8b6df…
api.s2cloud-amazon.com app-dimensiona.s3.sa-east-1.amazonaws.com bjj-files-production.s3.sa-east-1.amazonaws.com footracker-statics.s3.sa-east-1.amazonaws.com p-game.s3.sa-east-1.amazonaws.com s2cloud-amazon.com speedshare.oss-cn-hongkong.aliyuncs.com -
blog.malwarebytes.com/threat-analysis/2020/06/higaisa · otx.alienvault.com/pulse/5eda8caf8ef3aa0d8d0b8030 · virustotal.com/gui/file/df999d24bde96decdbb65287ca0986…
45.76.6.149:443 -
blog.malwarebytes.com/threat-analysis/2020/06/higaisa · otx.alienvault.com/pulse/5eda8caf8ef3aa0d8d0b8030 · virustotal.com/gui/file/df999d24bde96decdbb65287ca0986…
comcleanner.info sixindent.epizy.com zeplin.atwebpages.com -
blog.malwarebytes.com/threat-analysis/2020/06/higaisa · otx.alienvault.com/pulse/5eda8caf8ef3aa0d8d0b8030 · virustotal.com/gui/file/df999d24bde96decdbb65287ca0986…
goodhk.azurewebsites.net
Further reading 14
- attack.mitre.org/groups/G0126
- blog.malwarebytes.com/threat-analysis/2020/06/higaisa
- ptsecurity.com/ww-en/analytics/pt-esc-threat-intellige…
- zscaler.com/blogs/security-research/return-higaisa-…
- virustotal.com/gui/file/1e6c661d6981c0fa56c011c29536e5…
- virustotal.com/gui/file/f1d519f43c36e24a89b351f00059a1…
- github.com/StrikeReady-Inc/samples/blob/main/2024-…
- otx.alienvault.com/pulse/5eda8caf8ef3aa0d8d0b8030
- tgsoft.it/news/news_archivio.asp?id=1568&lang=eng
- virustotal.com/gui/file/9b73cd0be50e457d9355b702d8b6df…
- x.com/TuringAlex/status/1937442563285508449
- x.com/StrikeReadyLabs/status/1825885062186860…
- x.com/VirITeXplorer/status/1835667782853140788
- virustotal.com/gui/file/df999d24bde96decdbb65287ca0986…