AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Higaisa
Aliases: None listed
Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China, Japan, Russia, Poland, and other nations. Higaisa was first disclosed in early 2019 but is assessed to have operated as early as 2009.
Open interactive actor investigation
ATT&CK techniques
Visual BasicT1106
Native APIT1041
Exfiltration Over C2 ChannelT1574.002
DLL Side-LoadingT1124
System Time DiscoveryT1090.001
Internal ProxyT1204.002
Malicious FileT1027.013
Encrypted/Encoded FileT1053.005
Scheduled TaskT1082
System Information DiscoveryT1566.001
Spearphishing AttachmentT1071.001
Web ProtocolsT1001.003
Protocol or Service ImpersonationT1203
Exploitation for Client ExecutionT1029
Scheduled TransferT1059.007
JavaScriptT1027.001
Binary PaddingT1220
XSL Script ProcessingT1564.003
Hidden WindowT1573.001
Symmetric CryptographyT1547.001
Registry Run Keys / Startup FolderT1057
Process DiscoveryT1036.004
Masquerade Task or ServiceT1016
System Network Configuration DiscoveryT1059.003
Windows Command ShellT1140
Deobfuscate/Decode Files or Information
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Vulnerability Research & Exploit Development · explicit-idModule 11 — Email, web, API, data, and insider defense
Blue Team & Defensive Security · explicit-nameBinary formats, ABI, loaders, and mitigations
Vulnerability Research & Exploit Development · explicit-nameEmbedded, firmware, hardware, and update-chain research
Vulnerability Research & Exploit Development · explicit-nameFiles, parsers, serialization, URL fetching, and isolation
Secure Code & Application Security · explicit-nameImages, video, audio, geolocation, chronolocation, and media verification
OSINT & Reconnaissance · explicit-nameInfrastructure, network, resource, and availability security
AI Security · explicit-nameModule 7 — Privilege, lateral movement, and controlled impact
Red Team & Offensive Security · explicit-nameModule 7 — Endpoint defense and EDR
Blue Team & Defensive Security · explicit-nameControlled dynamic behavior and differential observation
Malware Analysis & Reverse Engineering · explicit-nameWindows endpoint and identity forensics
Digital Forensics & Incident Response (DFIR) · explicit-nameMobile and Android vulnerability research
Vulnerability Research & Exploit Development · explicit-name