Higaisa is malware delivered via spearphishing emails with malicious attachments, including LNK files, to induce user execution. It has also exploited CVE-2018-0798 for execution. Observed execution mechanisms include use of cmd.exe, VBScript, JavaScript, and XSL script processing to run VBScript. For persistence, Higaisa adds a spoofed binary to the Windows Startup folder and drops/adds officeupdate.exe as a Windows Scheduled Task. Defense evasion and concealment behaviors include use of a hidden window, Base64-encoded compressed payloads, certutil decoding, 16-byte XOR decryption, binary padding with null bytes before hashing, and masquerading a shellcode loader as svchast.exe to resemble svchost.exe. It also used a legitimate Microsoft Office 2007 package to side-load the OINFO12.OCX DLL. For command and control, Higaisa communicates over HTTP and HTTPS, uses FakeTLS-style protocol impersonation, encrypts C2 traffic with AES-128, and sends a victim computer identifier in the User-Agent string to the C2 server every 10 minutes. Discovery activity includes collecting the system GUID, computer name, volume serial number, proxy settings, ipconfig output, current system time, and attempting to identify the current process ID. It exfiltrates data over the established C2 channel.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Higaisa used HTTP and HTTPS to send data back to its C2 server... used AES-128 to encrypt C2 traffic... has exploited CVE-2018-0798 for execution.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
"...used tasklist to enumerate processes..."; "...used the ps command to list processes..."; "...calling CreateToolhelp32Snapshot... to enumerate the running processes..."
"admin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about the OS: ver >> %temp%\download systeminfo >> %temp%\download"; "ADVSTORESHELL can run Systeminfo to gather information about the victim."; "Kimsuky has enumerated drives, OS type, OS version, and other information using a script or the 'systeminfo' command."
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Higaisa used malicious e-mail attachments to lure victims into executing LNK files.
Backdoor used for command execution, persistence, discovery, encrypted C2 communications, and data exfiltration. Observed using spearphishing attachments (including LNK), scripting (cmd.exe/VBScript/JavaScript), scheduled tasks, and obfuscation/decoding (Base64 via certutil, XOR decryption).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.