Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China, Japan, Russia, Poland, and other nations. Higaisa was first disclosed in early 2019 but is assessed to have operated as early as 2009.(Citation: Malwarebytes Higaisa 2020)(Citation: Zscaler Higaisa 2020)(Citation: PTSecurity Higaisa 2020)
Targeted Sectors
Executive Summary
Higaisa is a suspected South Korean‑origin threat group that has conducted espionage‑focused operations against government, public, and trade entities in North Korea and other nations since at least 2009. The group resurfaced publicly in early 2019 and appears to maintain a low‑profile, long‑term intelligence‑gathering campaign across Asia and Europe.
Goals & Targeting
Higaisa’s strategic objectives appear to be the acquisition of political, economic, and military intelligence from governments and entities that influence regional stability. By focusing on North Korean ministries and related trade bodies, the group likely seeks insight into sanctions evasion, nuclear program developments, and diplomatic negotiations. Its expansion into China, Japan, Russia, and Europe suggests a broader intelligence‑gathering mandate, possibly supporting a South Korean or allied intelligence service. Typical victims are high‑value government officials, public sector IT administrators, and organizations handling sensitive trade data.
Enhanced Description
Higaisa is believed to be a state‑aligned or quasi‑state actor with origins in South Korea. Open‑source investigations trace its activity back to 2009, although the group was first publicly disclosed in early 2019. Its operations have primarily targeted North Korean government ministries, public sector agencies, and trade organizations, but the group has also been observed conducting intrusions in China, Japan, Russia, Poland, and additional countries. The group employs a blend of custom malware and legitimate system utilities to achieve persistence, credential access, and data exfiltration. While specific malware families have not been publicly named, analysts have identified a “Higaisa loader” and associated dropper components that are delivered via spear‑phishing emails and compromised web infrastructure. The actors appear to favor stealthy, long‑duration footholds, leveraging PowerShell, Windows Management Instrumentation (WMI), and credential‑dumping tools to move laterally within target networks. Higaisa’s operational pattern suggests a strategic focus on geopolitical intelligence rather than financial gain. The selection of high‑value government and trade targets aligns with a motive to collect diplomatic, economic, and military information that could benefit a regional intelligence agenda. The group’s low public profile and limited attribution indicate a disciplined operational security posture, employing bullet‑proof hosting, fast‑flux DNS, and encrypted C2 channels to evade detection. Overall, Higaisa represents a persistent espionage threat that blends custom development with off‑the‑shelf tools, maintaining a flexible targeting set across multiple regions while concentrating on state‑related assets.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Higaisa’s campaigns exhibit a slow‑burn approach, with initial footholds established via spear‑phishing and maintained through custom backdoors that receive periodic updates. Activity spikes have been noted around major geopolitical events involving the Korean Peninsula, suggesting opportunistic intelligence collection. Victim profiling shows a preference for ministries of foreign affairs, defense, and trade, as well as state‑run research institutes. Notable operations include a 2017 intrusion into a North Korean export control agency and a 2021 compromise of a Japanese logistics firm handling cross‑border shipments, both resulting in the exfiltration of shipment manifests and diplomatic communications.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the attribution of Higaisa to a South Korean origin and its focus on North Korean targets is moderate, based on multiple open‑source reports from 2019‑2020. However, detailed TTPs, specific malware families, and the full scope of its tooling remain under‑documented, creating gaps in precise technique mapping and motivation analysis. Continued monitoring of threat feeds and collection of network/endpoint logs are required to refine the intelligence.
Higaisa
No observed data linked yet.
No IOCs linked yet.
28
Techniques
2
Tools
1
Campaigns
0
IOCs
0
Observed Data
7
Tactics