Higaisa
Reports per quarter
Techniques seen in the last two years
- T1008 1 report reports only
- T1016 1 report in ATT&CK
- T1020 1 report reports only
- T1027 1 report reports only
- T1033 1 report reports only
- T1036 1 report reports only
- T1041 1 report in ATT&CK
- T1053 1 report reports only
- T1059 1 report reports only
- T1082 1 report in ATT&CK
Show all 15 techniques Show fewer
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2015-8651 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-8570 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-13382 KEV ransomware
- CVE-2018-13383 KEV ransomware
- CVE-2018-1579
- CVE-2018-8174 KEV ransomware
- CVE-2018-8373 KEV
- CVE-2019-11510 KEV ransomware
Show all 24 CVEs Show fewer
- CVE-2019-11539 KEV ransomware
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-17026 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2020-0601 KEV
- CVE-2020-0674 KEV
- CVE-2020-0796 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2024-4577 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ghost RAT (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
FINDING BEACONS IN THE DARK 1650728751599
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FINDING BEACONS IN THE DARK 1650728751599
-
Drawing a Dragon- Connecting the Dots to Find APT41
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Drawing a Dragon- Connecting the Dots to Find APT41
-
Earth Baku: An APT Group Targeting Indo-Pacific Countries With New Stealth Loaders and Backdoor
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Earth Baku: An APT Group Targeting Indo-Pacific Countries With New Stealth Loaders and Backdoor
-
ptsecurity.com-Higaisa or Winnti APT41 backdoors old and new
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ptsecurity.com-Higaisa or Winnti APT41 backdoors old and new
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
Show all 27 reports Show fewer
-
Higaisa or Winnti- APT41 backdoors, old and new
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Higaisa or Winnti- APT41 backdoors, old and new
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor nao-sec.org-Royal Road ReDive
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Royal Road! Re-Dive
-
cybersecurity-threatscape-2020-q1-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cybersecurity-threatscape-2020-q1-eng
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Deep-dive- The DarkHotel APT
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Return of the Higaisa APT
-
New LNK attack tied to Higaisa APT discovered - Malwarebytes Labs _ Malwarebytes Labs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor New LNK attack tied to Higaisa APT discovered - Malwarebytes Labs _ Malwarebytes Labs
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Gh0st Remains the Same
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor COVID-19 and New Year greetings- an investigation into the tools and methods used by the Higaisa group
-
New LNK attack tied to Higaisa APT discovered
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New LNK attack tied to Higaisa APT discovered
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor (cn)_higaisa_apt_report
Newest first. Details opens the report in Explore.