Higaisa__2020__New_LNK_attack_tied_to_Higaisa_APT_discovered_-_Malwarebytes_Labs_Malwarebytes_Labs.pdf
ID: 235a4da6-b8ed-4298-aa6b-06632083be94
STIX ID: report--235a4da6-b8ed-4298-aa6b-06632083be94
Threat Score
75/100
Uploaded: 2026-08-15
Published Date: 2020-06-05
Last Modified Date: 2020-06-05
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Malwarebytes analysis describes a May 2020 Higaisa APT campaign using spear-phished RAR archives containing malicious .lnk shortcuts that drop and decode a CAB payload (via a renamed certutil), extract a decoy PDF, deploy a small loader (svchast.exe) that reads and executes shellcode, and run a JS dropper to establish persistence and exfiltrate IP configuration to hardcoded C2 domains; the report includes process flow, file and network IOCs, assembly-level analysis of the loader and shellcode, and mappings to MITRE ATT&CK techniques.
