Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Honeybee

Also known as: G0072

Description

McAfee Advanced Threat Research analysts have discovered a new operation targeting humanitarian aid organizations and using North Korean political topics as bait to lure victims into opening malicious Microsoft Word documents. Our analysts have named this Operation Honeybee, based on the names of the malicious documents used in the attacks. Advanced Threat Research analysts have also discovered malicious documents authored by the same actor that indicate a tactical shift. These documents do not contain the typical lures by this actor, instead using Word compatibility messages to entice victims into opening them. The Advanced Threat Research team also observed a heavy concentration of the implant in Vietnam from January 15–17.

AI Analysis

· 1 week ago

Executive Summary

Honeybee, an unidentified cyber threat actor, primarily targets humanitarian aid organizations using North Korean政治 topics as bait. They employ malicious Microsoft Word documents to compromise victims, with observed activity in Vietnam around January 2023.

Goals & Targeting

Honeybee’s primary objective appears to be infiltrating humanitarian aid organizations, possibly for intelligence collection or disruption. Their use of North Korean political themes suggests a potential nexus with groups interested in that region's activities. The targeting of Vietnam highlights a strategic focus on Southeast Asian geographies, though broader regional interests cannot be ruled out.

Enhanced Description

Operation Honeybee is a newly identified campaign leveraging spear-phishing attacks against humanitarian aid groups. The attackers distribute .doc files named with politically charged North Korean themes, such as 'Meeting Minutes.doc' and 'Press Statement.doc.' These documents contain malicious macros that execute upon opening, indicating a focus on compromising sensitive organizational data. McAfee's research highlights a shift in战术, where more recent samples no longer include traditional lures but instead use compatibility messages to entice users to open the files.

Key Capabilities

  • Spear-phishing attacks using malicious Microsoft Word documents
  • Use of macros to deliver payloads
  • Shifts in tactics to avoid detection (e.g., removing traditional lures in favor of compatibility messages)
  • Focused operational activity within specific geographies

MITRE ATT&CK Tactics

Adversary Persistance
Credential Access
Exfiltration

ATT&CK Techniques

T1056.002
T1036

Software / Tooling

Malicious Microsoft Word Documents
Custom Malware (inferred from campaign TTPs)

Campaigns & Victims

Honeybee’s campaign demonstrates a sophisticated understanding of targeting specific sectors and geographies. Their shift in战术 suggests an adaptive approach to evade detection, with limited but significant activity observed in Southeast Asia. The focus on humanitarian aid groups indicates a potential interest in sensitive data or operational disruption.

IOC Patterns

  • Spear-phishing emails containing malicious Microsoft Word attachments
  • Document names referencing North Korean political themes
  • Use of macro-based infections for payload delivery

Recommended Actions

  • Implement robust email filtering and anti-macro protections in Microsoft Office documents
  • Educate users to recognize suspicious emails and document inconsistencies
  • Monitor network traffic for signs of lateral movement and exfiltration attempts
  • Conduct regular security audits on organizational assets, especially those within targeted sectors

Suggested Tags

APT
Spear-phishing
Humanitarian Sector Targeting
North Korea Thematic

Confidence Assessment

Confidence in Honeybee's identity and TTPs is moderate based on McAfee's research. Further analysis regarding their specific tools,完整 kill chain, and long-term objectives would enhance understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Backdoor / C2
APT
Spear-phishing
Humanitarian Sector Targeting
North Korea Thematic

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.