Honeybee__2018__Operation_Honeybee.pdf
ID: 141b133d-4cfb-40fe-99ea-a261cbe72d5b
STIX ID: report--141b133d-4cfb-40fe-99ea-a261cbe72d5b
Threat Score
80/100
Uploaded: 2026-08-19
Published Date: 2018-03-04
Last Modified Date: 2018-03-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
McAfee Advanced Threat Research discovered Operation Honeybee, a targeted malware campaign using malicious Word documents and VBA macros to deploy a SYSCON backdoor and persist via service DLL installation and UAC bypass; the campaign targeted humanitarian aid groups across multiple countries, used custom Base64-like encoding and stolen code-signing, and includes numerous IOCs (file hashes, domains, FTP/C2 listings) and detailed TTPs for detection and mitigation.
