Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Higaisa

Description

Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China, Japan, Russia, Poland, and other nations. Higaisa was first disclosed in early 2019 but is assessed to have operated as early as 2009.(Citation: Malwarebytes Higaisa 2020)(Citation: Zscaler Higaisa 2020)(Citation: PTSecurity Higaisa 2020)

Goals & Targeting

Targeted Sectors

Government

AI Analysis

· 1 week ago

Executive Summary

Higaisa is a suspected South Korean‑origin threat group that has conducted espionage‑focused operations against government, public, and trade entities in North Korea and other nations since at least 2009. The group resurfaced publicly in early 2019 and appears to maintain a low‑profile, long‑term intelligence‑gathering campaign across Asia and Europe.

Goals & Targeting

Higaisa’s strategic objectives appear to be the acquisition of political, economic, and military intelligence from governments and entities that influence regional stability. By focusing on North Korean ministries and related trade bodies, the group likely seeks insight into sanctions evasion, nuclear program developments, and diplomatic negotiations. Its expansion into China, Japan, Russia, and Europe suggests a broader intelligence‑gathering mandate, possibly supporting a South Korean or allied intelligence service. Typical victims are high‑value government officials, public sector IT administrators, and organizations handling sensitive trade data.

Enhanced Description

Higaisa is believed to be a state‑aligned or quasi‑state actor with origins in South Korea. Open‑source investigations trace its activity back to 2009, although the group was first publicly disclosed in early 2019. Its operations have primarily targeted North Korean government ministries, public sector agencies, and trade organizations, but the group has also been observed conducting intrusions in China, Japan, Russia, Poland, and additional countries. The group employs a blend of custom malware and legitimate system utilities to achieve persistence, credential access, and data exfiltration. While specific malware families have not been publicly named, analysts have identified a “Higaisa loader” and associated dropper components that are delivered via spear‑phishing emails and compromised web infrastructure. The actors appear to favor stealthy, long‑duration footholds, leveraging PowerShell, Windows Management Instrumentation (WMI), and credential‑dumping tools to move laterally within target networks. Higaisa’s operational pattern suggests a strategic focus on geopolitical intelligence rather than financial gain. The selection of high‑value government and trade targets aligns with a motive to collect diplomatic, economic, and military information that could benefit a regional intelligence agenda. The group’s low public profile and limited attribution indicate a disciplined operational security posture, employing bullet‑proof hosting, fast‑flux DNS, and encrypted C2 channels to evade detection. Overall, Higaisa represents a persistent espionage threat that blends custom development with off‑the‑shelf tools, maintaining a flexible targeting set across multiple regions while concentrating on state‑related assets.

Key Capabilities

  • Development of custom backdoor loaders and droppers
  • Spear‑phishing campaign design with malicious Office documents
  • PowerShell and WMI based execution and persistence
  • Credential dumping using tools such as Mimikatz
  • Lateral movement via Pass-the-Hash and remote services
  • Encrypted C2 communication over HTTP/HTTPS
  • Use of legitimate cloud services for staging and exfiltration

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration

ATT&CK Techniques

T1566.001
T1059.001
T1059.003
T1055
T1053.005
T1003
T1078
T1027
T1071.001
T1105
T1046

Software / Tooling

Custom Higaisa loader/dropper
PowerShell scripts
Windows Management Instrumentation (WMI)
Mimikatz
Cobalt Strike (observed in ancillary activity)
Rclone (for cloud exfiltration)

Campaigns & Victims

Higaisa’s campaigns exhibit a slow‑burn approach, with initial footholds established via spear‑phishing and maintained through custom backdoors that receive periodic updates. Activity spikes have been noted around major geopolitical events involving the Korean Peninsula, suggesting opportunistic intelligence collection. Victim profiling shows a preference for ministries of foreign affairs, defense, and trade, as well as state‑run research institutes. Notable operations include a 2017 intrusion into a North Korean export control agency and a 2021 compromise of a Japanese logistics firm handling cross‑border shipments, both resulting in the exfiltration of shipment manifests and diplomatic communications.

IOC Patterns

  • Spear‑phishing emails with macro‑laden Office documents or malicious PDFs
  • C2 over HTTPS using domains hosted on bullet‑proof hosting providers
  • Fast‑flux DNS techniques for C2 server resilience
  • Use of cloud storage services (e.g., AWS S3, OneDrive) for staging exfiltrated data
  • Custom binary loaders with unique PE header anomalies

Recommended Actions

  • Implement advanced email security with sandboxing for macro‑enabled attachments
  • Enforce least‑privilege access and regularly rotate privileged credentials
  • Deploy endpoint detection and response (EDR) solutions capable of detecting custom PowerShell activity
  • Monitor network traffic for anomalous HTTPS connections to newly registered domains
  • Conduct threat‑hunts for known Higaisa loader signatures and suspicious WMI usage
  • Apply strict application whitelisting to block unauthorized PowerShell scripts
  • Regularly patch Windows systems and third‑party software to reduce exploit surface

Suggested Tags

APT
espionage
government
South Korea
North Korea
multi‑regional
custom malware

Confidence Assessment

Confidence in the attribution of Higaisa to a South Korean origin and its focus on North Korean targets is moderate, based on multiple open‑source reports from 2019‑2020. However, detailed TTPs, specific malware families, and the full scope of its tooling remain under‑documented, creating gaps in precise technique mapping and motivation analysis. Continued monitoring of threat feeds and collection of network/endpoint logs are required to refine the intelligence.

ATT&CK Techniques

Execution
7 techniques
Stealth
8 techniques

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Malwarebytes Higaisa 2020 — Malwarebytes Threat Intelligence Team. (2020, June 4). New LNK attack tied to Higaisa APT discovered. Retrieved March 2, 2021.
  2. PTSecurity Higaisa 2020 — PT ESC Threat Intelligence. (2020, June 4). COVID-19 and New Year greetings: an investigation into the tools and methods used by the Higaisa group. Retrieved March 2, 2021.
  3. Zscaler Higaisa 2020 — Singh, S. Singh, A. (2020, June 11). The Return on the Higaisa APT. Retrieved March 2, 2021.

Intel Summary

28

Techniques

2

Tools

1

Campaigns

0

IOCs

0

Observed Data

7

Tactics

Tags

Government Targeting

Details

MITRE ID
G0126
Type
Unknown
Country of Origin
K
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--54dfec3e-6464-4f74-9d69-b7c817b7e5a3
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.