ATT&CKCampaignsOperation Honeybee

Operation Honeybee

C0006

Campaign, Aug 2017 to Feb 2018.View on attack.mitre.org

About this campaign

Operation Honeybee was a campaign that targeted humanitarian aid and inter-Korean affairs organizations from at least late 2017 through early 2018. Operation Honeybee initially targeted South Korea, but expanded to include Vietnam, Singapore, Japan, Indonesia, Argentina, and Canada. Security researchers assessed the threat actors were likely Korean speakers based on metadata used in both lure documents and executables, and named the campaign "Honeybee" after the author name discovered in malicious Word documents.

Techniques used28

Procedure examples28

TechniqueProcedure example
T1005
Data from Local System

During Operation Honeybee, the threat actors collected data from compromised hosts.

T1027.013
Encrypted/Encoded File

During Operation Honeybee, the threat actors used Base64 to encode files with a custom key.

T1036
Masquerading

During Operation Honeybee, the threat actors modified the MaoCheng dropper so its icon appeared as a Word document.

T1036.005
Match Legitimate Resource Name or Location

During Operation Honeybee, the threat actors used a legitimate Windows executable and secure directory for their payloads to bypass UAC.

T1041
Exfiltration Over C2 Channel

During Operation Honeybee, the threat actors uploaded stolen files to their C2 servers.

T1057
Process Discovery

During Operation Honeybee, the threat actors obtained a list of running processes on a victim machine using `cmd /c tasklist > %temp%\temp.ini`.

T1059.003
Windows Command Shell

During Operation Honeybee, various implants used batch scripting and `cmd.exe` for execution.

T1059.005
Visual Basic

For Operation Honeybee, the threat actors used a Visual Basic script embedded within a Word document to download an implant.

T1070.004
File Deletion

During Operation Honeybee, the threat actors used batch files that reduced their fingerprint on a compromised system by deleting malware-related files.

T1071.002
File Transfer Protocols

During Operation Honeybee, the threat actors had the ability to use FTP for C2.

T1074.001
Local Data Staging

During Operation Honeybee, stolen data was copied into a text file using the format `From <COMPUTER-NAME> (<Month>-<Day> <Hour>-<Minute>-<Second>).txt` prior to compression, encoding, and exfiltration.

T1082
System Information Discovery

During Operation Honeybee, the threat actors collected the computer name, OS, and other system information using `cmd /c systeminfo > %temp%\ temp.ini`.

T1083
File and Directory Discovery

During Operation Honeybee, the threat actors used a malicious DLL to search for files with specific keywords.

T1105
Ingress Tool Transfer

During Operation Honeybee, the threat actors downloaded additional malware and malicious scripts onto a compromised host.

T1106
Native API

During Operation Honeybee, the threat actors deployed malware that used API calls, including `CreateProcessAsUser`.

View all 28 procedure examples

Attributed groups0

MITRE does not attribute this campaign to a group.

Software5

References1

  1. McAfee Honeybee Open source
    Sherstobitoff, R. (2018, March 02). McAfee Uncovers Operation Honeybee, a Malicious Document Campaign Targeting Humanitarian Aid Groups. Retrieved May 16, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.