Return of the Higaisa APT
ID: e7cbb885-b281-5c6f-b2bc-8e22c4cd6916
STIX ID: report--e7cbb885-b281-5c6f-b2bc-8e22c4cd6916
Feed Name: Zscaler Security Research Blog
**Executive summary:** This report analyzes an LNK-based espionage campaign (May 2020) attributed to the Higaisa APT that uses malicious LNK files inside RAR attachments to drop a multi-stage backdoor (svchast.exe loader + shellcode) which employs anti-analysis, a complex cryptographic key-derivation routine, and a FakeTLS-style C2 channel created by duplicating socket handles; the report includes technical analysis, YARA hunting rules, MITRE ATT&CK mappings, and a set of IOCs (file hashes, URLs, C2 addresses) for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
