Also known as: G0072
McAfee Advanced Threat Research analysts have discovered a new operation targeting humanitarian aid organizations and using North Korean political topics as bait to lure victims into opening malicious Microsoft Word documents. Our analysts have named this Operation Honeybee, based on the names of the malicious documents used in the attacks. Advanced Threat Research analysts have also discovered malicious documents authored by the same actor that indicate a tactical shift. These documents do not contain the typical lures by this actor, instead using Word compatibility messages to entice victims into opening them. The Advanced Threat Research team also observed a heavy concentration of the implant in Vietnam from January 15–17.
Executive Summary
Honeybee, an unidentified cyber threat actor, primarily targets humanitarian aid organizations using North Korean政治 topics as bait. They employ malicious Microsoft Word documents to compromise victims, with observed activity in Vietnam around January 2023.
Goals & Targeting
Honeybee’s primary objective appears to be infiltrating humanitarian aid organizations, possibly for intelligence collection or disruption. Their use of North Korean political themes suggests a potential nexus with groups interested in that region's activities. The targeting of Vietnam highlights a strategic focus on Southeast Asian geographies, though broader regional interests cannot be ruled out.
Enhanced Description
Operation Honeybee is a newly identified campaign leveraging spear-phishing attacks against humanitarian aid groups. The attackers distribute .doc files named with politically charged North Korean themes, such as 'Meeting Minutes.doc' and 'Press Statement.doc.' These documents contain malicious macros that execute upon opening, indicating a focus on compromising sensitive organizational data. McAfee's research highlights a shift in战术, where more recent samples no longer include traditional lures but instead use compatibility messages to entice users to open the files.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Honeybee’s campaign demonstrates a sophisticated understanding of targeting specific sectors and geographies. Their shift in战术 suggests an adaptive approach to evade detection, with limited but significant activity observed in Southeast Asia. The focus on humanitarian aid groups indicates a potential interest in sensitive data or operational disruption.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Honeybee's identity and TTPs is moderate based on McAfee's research. Further analysis regarding their specific tools,完整 kill chain, and long-term objectives would enhance understanding.
No techniques linked yet.
No tools linked yet.
Honeybee
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
0
IOCs
0
Observed Data
0
Tactics