LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0126: Higaisa

Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China, Japan, Russia, Poland, and other nations. Higaisa was first disclosed in early 2019 but is assessed to have operated as early as 2009.[1][2][3]

EnterpriseG0126GroupObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G0126: Higaisa describes [Higaisa](https://attack.mitre.org/groups/G0126) is a threat group suspected to have South Korean origins. [Higaisa](https://attack.mitre.org/groups/G0126) has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China, Japan, Russia, Poland, and other nations. [Higaisa](https://attack.mitre.org/groups/G0126) was first disclosed in early 2019 but is assessed to have operated as early as 2009.(Citation: Malwarebytes Higaisa 2020)(Citation: Zscaler Higais...

Executive priority

G0126: Higaisa is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G0126: Higaisa by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G0126: Higaisa appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Higaisa

Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China, Japan, Russia, Poland, and other nations. Higaisa was first disclosed in early 2019 but is assessed to have operated as early as 2009.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

28 rows
DomainIDNameRelationship / procedure
EnterpriseT1059.005Visual BasicSub-technique

Higaisa has used VBScript code on the victim's machine.[3]

EnterpriseT1106Native API

Higaisa has called various native OS APIs.[2]

EnterpriseT1041Exfiltration Over C2 Channel

Higaisa exfiltrated data over its C2 channel.[2]

EnterpriseT1574.001DLLSub-technique

Higaisa’s JavaScript file used a legitimate Microsoft Office 2007 package to side-load the OINFO12.OCX dynamic link library.[3]

EnterpriseT1124System Time Discovery

Higaisa used a function to gather the current time.[2]

EnterpriseT1090.001Internal ProxySub-technique

Higaisa discovered system proxy settings and used them if available.[2]

EnterpriseT1204.002Malicious FileSub-technique

Higaisa used malicious e-mail attachments to lure victims into executing LNK files.[1][2]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

Higaisa used Base64 encoded compressed payloads.[1][2]

EnterpriseT1053.005Scheduled TaskSub-technique

Higaisa dropped and added officeupdate.exe to scheduled tasks.[1][2]

EnterpriseT1082System Information Discovery

Higaisa collected the system GUID and computer name.[3][1]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

Higaisa has sent spearphishing emails containing malicious attachments.[1][2]

EnterpriseT1071.001Web ProtocolsSub-technique

Higaisa used HTTP and HTTPS to send data back to its C2 server.[1][2]

EnterpriseT1001.003Protocol or Service ImpersonationSub-technique

Higaisa used a FakeTLS session for C2 communications.[2]

EnterpriseT1203Exploitation for Client Execution

Higaisa has exploited CVE-2018-0798 for execution.[3]

EnterpriseT1029Scheduled Transfer

Higaisa sent the victim computer identifier in a User-Agent string back to the C2 server every 10 minutes.[3]

EnterpriseT1059.007JavaScriptSub-technique

Higaisa used JavaScript to execute additional files.[1][2][3]

EnterpriseT1027.001Binary PaddingSub-technique

Higaisa performed padding with null bytes before calculating its hash.[2]

EnterpriseT1027.015CompressionSub-technique

Higaisa used Base64 encoded compressed payloads.[1][2]

EnterpriseT1220XSL Script Processing

Higaisa used an XSL file to run VBScript code.[3]

EnterpriseT1564.003Hidden WindowSub-technique

Higaisa used a payload that creates a hidden window.[3]

EnterpriseT1573.001Symmetric CryptographySub-technique

Higaisa used AES-128 to encrypt C2 traffic.[2]

EnterpriseT1680Local Storage Discovery

Higaisa collected the system volume serial number.[3][1]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Higaisa added a spoofed binary to the start-up folder for persistence.[1][2]

EnterpriseT1057Process Discovery

Higaisa’s shellcode attempted to find the process ID of the current process.[2]

EnterpriseT1036.004Masquerade Task or ServiceSub-technique

Higaisa named a shellcode loader binary svchast.exe to spoof the legitimate svchost.exe.[1][2]

EnterpriseT1016System Network Configuration Discovery

Higaisa used ipconfig to gather network configuration information.[1][2]

EnterpriseT1059.003Windows Command ShellSub-technique

Higaisa used cmd.exe for execution.[1][2][3]

EnterpriseT1140Deobfuscate/Decode Files or Information

Higaisa used certutil to decode Base64 binaries at runtime and a 16-byte XOR key to decrypt data.[1][2]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0160: certutil

certutil is a command-line utility that can be used to obtain certificate authority information and configure Certificate Services. [1]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.2
Created
Modified
Raw hash
17e546bb3ab09c81...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.2Current bundle17e546bb3ab0…
19.11.2Older bundledf717a491055…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Malwarebytes Higaisa 2020

    Malwarebytes Threat Intelligence Team. (2020, June 4). New LNK attack tied to Higaisa APT discovered. Retrieved March 2, 2021.

    Open source URL
  2. [2]
    Zscaler Higaisa 2020

    Singh, S. Singh, A. (2020, June 11). The Return on the Higaisa APT. Retrieved March 2, 2021.

    Open source URL
  3. [3]
    PTSecurity Higaisa 2020

    PT ESC Threat Intelligence. (2020, June 4). COVID-19 and New Year greetings: an investigation into the tools and methods used by the Higaisa group. Retrieved March 2, 2021.

    Open source URL
  4. [4]
    mitre-attackG0126
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.