G0126 · 26 ATT&CK techniques · 0 correlated reports

Higaisa

Aliases: None listed

Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China, Japan, Russia, Poland, and other nations. Higaisa was first disclosed in early 2019 but is assessed to have operated as early as 2009.

Open interactive actor investigation

ATT&CK techniques

Correlated CTI and IR reports

Continue the investigation