THREAT_ACTOR · G0126
Higaisa
Also known as: Higaisa
Profile
Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China, Japan, Russia, Poland, and other nations. Higaisa was first disclosed in early 2019 but is assessed to have operated as early as 2009.
MITRE ATT&CK ↗Techniques
28 ATT&CK techniques attributed to this actor.
T1001.003 Protocol or Service ImpersonationT1016 System Network Configuration DiscoveryT1027.001 Binary PaddingT1027.013 Encrypted/Encoded FileT1027.015 CompressionT1029 Scheduled TransferT1036.004 Masquerade Task or ServiceT1041 Exfiltration Over C2 ChannelT1053.005 Scheduled TaskT1057 Process DiscoveryT1059.003 Windows Command ShellT1059.005 Visual BasicT1059.007 JavaScriptT1071.001 Web ProtocolsT1082 System Information DiscoveryT1090.001 Internal ProxyT1106 Native APIT1124 System Time DiscoveryT1140 Deobfuscate/Decode Files or InformationT1203 Exploitation for Client ExecutionT1204.002 Malicious FileT1220 XSL Script ProcessingT1547.001 Registry Run Keys / Startup FolderT1564.003 Hidden WindowT1566.001 Spearphishing AttachmentT1573.001 Symmetric CryptographyT1574.001 DLLT1680 Local Storage Discovery
Software
3 malware/tools attributed to this actor.
PlugXgh0st RATcertutil
Related corpus activity
10,120 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Higaisa.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 10,120.