logo

Return of the Higaisa APT

ID: e7cbb885-b281-5c6f-b2bc-8e22c4cd6916

STIX ID: report--e7cbb885-b281-5c6f-b2bc-8e22c4cd6916

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive summary:** This report analyzes an LNK-based espionage campaign (May 2020) attributed to the Higaisa APT that uses malicious LNK files inside RAR attachments to drop a multi-stage backdoor (svchast.exe loader + shellcode) which employs anti-analysis, a complex cryptographic key-derivation routine, and a FakeTLS-style C2 channel created by duplicating socket handles; the report includes technical analysis, YARA hunting rules, MITRE ATT&CK mappings, and a set of IOCs (file hashes, URLs, C2 addresses) for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.