Uptime Hamster: 10d 15h 51mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Higaisa

Higaisa

1 incidentes 1 paises 0 sectores apt KR Ultimo: 2026-05-25
Aliases: APT HIGAISA
Ver en IntelTracker → APTTrail →
Higaisa is a cyber espionage group, first publicly disclosed in early 2019, though its activities are assessed to have begun as early as 2009. The group is believed with high confidence to be of South Korean origin, primarily motivated by intelligence gathering related to North Korean interests. Higaisa notably distinguishes itself by combining commodity tools such as Gh0st RAT with custom obfuscation techniques and living-off-the-land binaries, and it has developed mobile malware capabilities. The group is tracked by MITRE ATT&CK under the identifier G0126.

Aliases del actor

APT HIGAISA

Actores similares

apt-higaisaactor · 1apt-45actor · 2apt-c-27actor · 2apt-c-01actor · 2apt-c-12actor · 1apt-18actor · 1apt-1877teamactor · 1apt-27actor · 1apt-30actor · 1apt-38actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownblog.malwarebytes.comAPT HIGAISA indicators and references
Repositoriounknowngithub.comAPT HIGAISA indicators and references
DLS / leak siteunknownotx.alienvault.comAPT HIGAISA indicators and references
DLS / leak siteunknownwww.tgsoft.itAPT HIGAISA indicators and references
DLS / leak siteunknownwww.virustotal.comAPT HIGAISA indicators and references
DLS / leak siteunknownwww.virustotal.comAPT HIGAISA indicators and references
DLS / leak siteunknownwww.virustotal.comAPT HIGAISA indicators and references
DLS / leak siteunknownwww.virustotal.comAPT HIGAISA indicators and references
X/Twitterunknownx.comAPT HIGAISA indicators and references
X/Twitterunknownx.comAPT HIGAISA indicators and references
X/Twitterunknownx.comAPT HIGAISA indicators and references
Repositoriounknowngithub.comAPT HIGAISA indicators and references
DLS / leak siteunknownraw.githubusercontent.comAPT HIGAISA indicators and references
X/Twitterunknown152.42.226.161APTTrailReferenciashttpsAPT HIGAISA indicators and references
Malware asociado
PlugX, PlugX, PlugX, PlugX
Tecnicas MITRE
T1036.004, T1680, T1547.001, T1573, T1027.013, T1204.002
CVEs relacionadas
CVE-2023-20198
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

China (1)

Paises objetivo (SOCRadar)

AustraliaSwitzerlandChinaHong KongIndiaJapanKorea, Democratic People's Republic ofKorea, Republic ofNepalPhilippines

Sectores objetivo (SOCRadar)

Other Information ServicesSoftware PublishersManufacturingElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationWholesale TradeEnergy & Utilities InsuranceNational Security&International AffairsCivic&Social Organizations