Campaign · all campaigns
Operation HoneybeeC0006 unknown
aka Operation Honeybee
Last updated: 2026-08-20
About this actor
[Operation Honeybee](https://attack.mitre.org/campaigns/C0006) was a campaign that targeted humanitarian aid and inter-Korean affairs organizations from at least late 2017 through early 2018. [Operation Honeybee](https://attack.mitre.org/campaigns/C0006) initially targeted South Korea, but expanded to include Vietnam, Singapore, Japan, Indonesia, Argentina, and Canada. Security researchers assessed the threat actors were likely Korean speakers based on metadata used in both lure documents and executables, and named the campaign "Honeybee" after the author name discovered in malicious Word documents.(Citation: McAfee Honeybee)
Source: MITRE ATT&CK
How we know this
- Data origin
- MITRE ATT&CK campaign Imported from the MITRE ATT&CK STIX bundle as a campaign object.
- Techniques
- MITRE ATT&CK STIX mappings — 43 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1005Data from Local System ↗T1027Obfuscated Files or Information ↗T1027.013Encrypted/Encoded File ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1041Exfiltration Over C2 Channel ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.003Windows Command Shell ↗T1059.005Visual Basic ↗T1070Indicator Removal ↗T1070.004File Deletion ↗T1071Application Layer Protocol ↗T1071.002File Transfer Protocols ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1082System Information Discovery ↗T1083File and Directory Discovery ↗T1105Ingress Tool Transfer ↗T1106Native API ↗T1112Modify Registry ↗T1140Deobfuscate/Decode Files or Information ↗T1204User Execution ↗T1204.002Malicious File ↗T1543Create or Modify System Process ↗T1543.003Windows Service ↗T1548Abuse Elevation Control Mechanism ↗T1548.002Bypass User Account Control ↗T1553Subvert Trust Controls ↗T1553.002Code Signing ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1569System Services ↗T1569.002Service Execution ↗T1574Hijack Execution Flow ↗T1574.011Services Registry Permissions Weakness ↗T1583Acquire Infrastructure ↗T1583.001Domains ↗T1583.004Server ↗T1585Establish Accounts ↗T1585.002Email Accounts ↗T1588Obtain Capabilities ↗T1588.004Digital Certificates ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 24 / 43 | 56% |
CM-2 | 23 / 43 | 53% |
SI-3 | 23 / 43 | 53% |
CM-6 | 20 / 43 | 47% |
AC-6 | 19 / 43 | 44% |
CM-7 | 18 / 43 | 42% |
AC-3 | 17 / 43 | 40% |
AC-2 | 16 / 43 | 37% |
CA-7 | 16 / 43 | 37% |
SI-7 | 16 / 43 | 37% |
CM-5 | 10 / 43 | 23% |
AC-5 | 9 / 43 | 21% |
SI-10 | 9 / 43 | 21% |
SI-2 | 9 / 43 | 21% |
IA-2 | 8 / 43 | 19% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- APT41 DUST 0.31
- APT38 0.30
- menuPass 0.30
- Patchwork 0.29
- WIRTE 0.29