Cyber Resilience

Threat actor · all actors

HigaisaG0126 state

🇰🇷 KR

aka Higaisa

Last updated: 2026-08-20

0attributed CVEs
41ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

The organization often uses important North Korean time nodes such as holidays and North Korea to conduct fishing activities. The bait includes New Year blessings, Lantern blessings, North Korean celebrations, and important news, overseas personnel contact lists and so on. In addition, the attack organization also has the attack capability of the mobile terminal. The targets of the attack also include diplomatic entities related to North Korea (such as embassy officials in various places), government officials, human rights organizations, North Korean residents abroad, and traders. The victim countries currently monitored include China, North Korea, Japan, Nepal, Singapore, Russia, Poland, Switzerland, etc.

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G0126

Unclassifiedno scheme matched

Higaisa

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 41 ATT&CK techniques on file.
Named victims
None on file.

See how actor data is built for the full pipeline.

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-427 / 4166%
CM-225 / 4161%
CM-625 / 4161%
SI-325 / 4161%
CA-720 / 4149%
CM-720 / 4149%
AC-416 / 4139%
SC-715 / 4137%
SI-713 / 4132%
SI-1012 / 4129%
AC-311 / 4127%
AC-611 / 4127%
SI-210 / 4124%
AC-29 / 4122%
RA-58 / 4120%

Co-occurring actors

None.

Similar actors