Campaign, Aug 2017 to Feb 2018.View on attack.mitre.org
Operation Honeybee was a campaign that targeted humanitarian aid and inter-Korean affairs organizations from at least late 2017 through early 2018. Operation Honeybee initially targeted South Korea, but expanded to include Vietnam, Singapore, Japan, Indonesia, Argentina, and Canada. Security researchers assessed the threat actors were likely Korean speakers based on metadata used in both lure documents and executables, and named the campaign "Honeybee" after the author name discovered in malicious Word documents.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
During Operation Honeybee, the threat actors collected data from compromised hosts. |
| T1027.013 Encrypted/Encoded File |
During Operation Honeybee, the threat actors used Base64 to encode files with a custom key. |
| T1036 Masquerading |
During Operation Honeybee, the threat actors modified the MaoCheng dropper so its icon appeared as a Word document. |
| T1036.005 Match Legitimate Resource Name or Location |
During Operation Honeybee, the threat actors used a legitimate Windows executable and secure directory for their payloads to bypass UAC. |
| T1041 Exfiltration Over C2 Channel |
During Operation Honeybee, the threat actors uploaded stolen files to their C2 servers. |
| T1057 Process Discovery |
During Operation Honeybee, the threat actors obtained a list of running processes on a victim machine using `cmd /c tasklist > %temp%\temp.ini`. |
| T1059.003 Windows Command Shell |
During Operation Honeybee, various implants used batch scripting and `cmd.exe` for execution. |
| T1059.005 Visual Basic |
For Operation Honeybee, the threat actors used a Visual Basic script embedded within a Word document to download an implant. |
| T1070.004 File Deletion |
During Operation Honeybee, the threat actors used batch files that reduced their fingerprint on a compromised system by deleting malware-related files. |
| T1071.002 File Transfer Protocols |
During Operation Honeybee, the threat actors had the ability to use FTP for C2. |
| T1074.001 Local Data Staging |
During Operation Honeybee, stolen data was copied into a text file using the format `From <COMPUTER-NAME> (<Month>-<Day> <Hour>-<Minute>-<Second>).txt` prior to compression, encoding, and exfiltration. |
| T1082 System Information Discovery |
During Operation Honeybee, the threat actors collected the computer name, OS, and other system information using `cmd /c systeminfo > %temp%\ temp.ini`. |
| T1083 File and Directory Discovery |
During Operation Honeybee, the threat actors used a malicious DLL to search for files with specific keywords. |
| T1105 Ingress Tool Transfer |
During Operation Honeybee, the threat actors downloaded additional malware and malicious scripts onto a compromised host. |
| T1106 Native API |
During Operation Honeybee, the threat actors deployed malware that used API calls, including `CreateProcessAsUser`. |
MITRE does not attribute this campaign to a group.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.