logo

Honeybee__2018__Operation_Honeybee.pdf

ID: 141b133d-4cfb-40fe-99ea-a261cbe72d5b

STIX ID: report--141b133d-4cfb-40fe-99ea-a261cbe72d5b

Threat Score

80/100

Uploaded: 2026-08-19

Published Date: 2018-03-04

Last Modified Date: 2018-03-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
McAfee Advanced Threat Research discovered Operation Honeybee, a targeted malware campaign using malicious Word documents and VBA macros to deploy a SYSCON backdoor and persist via service DLL installation and UAC bypass; the campaign targeted humanitarian aid groups across multiple countries, used custom Base64-like encoding and stolen code-signing, and includes numerous IOCs (file hashes, domains, FTP/C2 listings) and detailed TTPs for detection and mitigation.