logo

Higaisa__2020__New_LNK_attack_tied_to_Higaisa_APT_discovered_-_Malwarebytes_Labs_Malwarebytes_Labs.pdf

ID: 235a4da6-b8ed-4298-aa6b-06632083be94

STIX ID: report--235a4da6-b8ed-4298-aa6b-06632083be94

Threat Score

75/100

Uploaded: 2026-08-15

Published Date: 2020-06-05

Last Modified Date: 2020-06-05

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Malwarebytes analysis describes a May 2020 Higaisa APT campaign using spear-phished RAR archives containing malicious .lnk shortcuts that drop and decode a CAB payload (via a renamed certutil), extract a decoy PDF, deploy a small loader (svchast.exe) that reads and executes shellcode, and run a JS dropper to establish persistence and exfiltrate IP configuration to hardcoded C2 domains; the report includes process flow, file and network IOCs, assembly-level analysis of the loader and shellcode, and mappings to MITRE ATT&CK techniques.