Sherstobitoff, R. (2018, March 02). McAfee Uncovers Operation Honeybee, a Malicious Document Campaign Targeting Humanitarian Aid Groups. Retrieved May 16, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors collected data from compromised hosts. |
| T1027.013 Encrypted/Encoded File |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used Base64 to encode files with a custom key. |
| T1036 Masquerading |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors modified the MaoCheng dropper so its icon appeared as a Word document. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used a legitimate Windows executable and secure directory for their payloads to bypass UAC. |
| T1041 Exfiltration Over C2 Channel |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors uploaded stolen files to their C2 servers. |
| T1057 Process Discovery |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors obtained a list of running processes on a victim machine using `cmd /c tasklist > %temp%\temp.ini`. |
| T1059.003 Windows Command Shell |
CampaignOperation Honeybee | During Operation Honeybee, various implants used batch scripting and `cmd.exe` for execution. |
| T1059.005 Visual Basic |
CampaignOperation Honeybee | For Operation Honeybee, the threat actors used a Visual Basic script embedded within a Word document to download an implant. |
| T1070.004 File Deletion |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used batch files that reduced their fingerprint on a compromised system by deleting malware-related files. |
| T1071.002 File Transfer Protocols |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors had the ability to use FTP for C2. |
| T1074.001 Local Data Staging |
CampaignOperation Honeybee | During Operation Honeybee, stolen data was copied into a text file using the format `From <COMPUTER-NAME> (<Month>-<Day> <Hour>-<Minute>-<Second>).txt` prior to compression, encoding, and exfiltration. |
| T1082 System Information Discovery |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors collected the computer name, OS, and other system information using `cmd /c systeminfo > %temp%\ temp.ini`. |
| T1083 File and Directory Discovery |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used a malicious DLL to search for files with specific keywords. |
| T1105 Ingress Tool Transfer |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors downloaded additional malware and malicious scripts onto a compromised host. |
| T1106 Native API |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors deployed malware that used API calls, including `CreateProcessAsUser`. |
| T1112 Modify Registry |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used batch files that modified registry keys. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignOperation Honeybee | During Operation Honeybee, malicious files were decoded prior to execution. |
| T1204.002 Malicious File |
CampaignOperation Honeybee | During Operation Honeybee, threat actors relied on a victim to enable macros within a malicious Word document. |
| T1543.003 Windows Service |
CampaignOperation Honeybee | During Operation Honeybee, threat actors installed DLLs and backdoors as Windows services. |
| T1548.002 Bypass User Account Control |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used the malicious NTWDBLIB.DLL and `cliconfig.exe` to bypass UAC protections. |
| T1553.002 Code Signing |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors deployed the MaoCheng dropper with a stolen Adobe Systems digital signature. |
| T1560.001 Archive via Utility |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors uses zip to pack collected files before exfiltration. |
| T1569.002 Service Execution |
CampaignOperation Honeybee | During Operation Honeybee, threat actors ran |
| T1574.011 Services Registry Permissions Weakness |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used a batch file that modified the COMSysApp service to load a malicious ipnet.dll payload and to load a DLL into the `svchost.exe` process. |
| T1583.001 Domains |
CampaignOperation Honeybee | During Operation Honeybee, threat actors registered domains for C2. |
| T1583.004 Server |
CampaignOperation Honeybee | For Operation Honeybee, at least one identified persona was used to register for a free account for a control server. |
| T1585.002 Email Accounts |
CampaignOperation Honeybee | During Operation Honeybee, attackers created email addresses to register for a free account for a control server used for the implants. |
| T1588.004 Digital Certificates |
CampaignOperation Honeybee | For Operation Honeybee, the threat actors stole a digital signature from Adobe Systems to use with their MaoCheng dropper. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.