ATT&CKReferencesMcAfee Honeybee

McAfee Honeybee

Sherstobitoff, R. (2018, March 02). McAfee Uncovers Operation Honeybee, a Malicious Document Campaign Targeting Humanitarian Aid Groups. Retrieved May 16, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns1

Procedure examples28

TechniqueUsed byProcedure example
T1005
Data from Local System
CampaignOperation Honeybee

During Operation Honeybee, the threat actors collected data from compromised hosts.

T1027.013
Encrypted/Encoded File
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used Base64 to encode files with a custom key.

T1036
Masquerading
CampaignOperation Honeybee

During Operation Honeybee, the threat actors modified the MaoCheng dropper so its icon appeared as a Word document.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used a legitimate Windows executable and secure directory for their payloads to bypass UAC.

T1041
Exfiltration Over C2 Channel
CampaignOperation Honeybee

During Operation Honeybee, the threat actors uploaded stolen files to their C2 servers.

T1057
Process Discovery
CampaignOperation Honeybee

During Operation Honeybee, the threat actors obtained a list of running processes on a victim machine using `cmd /c tasklist > %temp%\temp.ini`.

T1059.003
Windows Command Shell
CampaignOperation Honeybee

During Operation Honeybee, various implants used batch scripting and `cmd.exe` for execution.

T1059.005
Visual Basic
CampaignOperation Honeybee

For Operation Honeybee, the threat actors used a Visual Basic script embedded within a Word document to download an implant.

T1070.004
File Deletion
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used batch files that reduced their fingerprint on a compromised system by deleting malware-related files.

T1071.002
File Transfer Protocols
CampaignOperation Honeybee

During Operation Honeybee, the threat actors had the ability to use FTP for C2.

T1074.001
Local Data Staging
CampaignOperation Honeybee

During Operation Honeybee, stolen data was copied into a text file using the format `From <COMPUTER-NAME> (<Month>-<Day> <Hour>-<Minute>-<Second>).txt` prior to compression, encoding, and exfiltration.

T1082
System Information Discovery
CampaignOperation Honeybee

During Operation Honeybee, the threat actors collected the computer name, OS, and other system information using `cmd /c systeminfo > %temp%\ temp.ini`.

T1083
File and Directory Discovery
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used a malicious DLL to search for files with specific keywords.

T1105
Ingress Tool Transfer
CampaignOperation Honeybee

During Operation Honeybee, the threat actors downloaded additional malware and malicious scripts onto a compromised host.

T1106
Native API
CampaignOperation Honeybee

During Operation Honeybee, the threat actors deployed malware that used API calls, including `CreateProcessAsUser`.

T1112
Modify Registry
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used batch files that modified registry keys.

T1140
Deobfuscate/Decode Files or Information
CampaignOperation Honeybee

During Operation Honeybee, malicious files were decoded prior to execution.

T1204.002
Malicious File
CampaignOperation Honeybee

During Operation Honeybee, threat actors relied on a victim to enable macros within a malicious Word document.

T1543.003
Windows Service
CampaignOperation Honeybee

During Operation Honeybee, threat actors installed DLLs and backdoors as Windows services.

T1548.002
Bypass User Account Control
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used the malicious NTWDBLIB.DLL and `cliconfig.exe` to bypass UAC protections.

T1553.002
Code Signing
CampaignOperation Honeybee

During Operation Honeybee, the threat actors deployed the MaoCheng dropper with a stolen Adobe Systems digital signature.

T1560.001
Archive via Utility
CampaignOperation Honeybee

During Operation Honeybee, the threat actors uses zip to pack collected files before exfiltration.

T1569.002
Service Execution
CampaignOperation Honeybee

During Operation Honeybee, threat actors ran sc start to start the COMSysApp as part of the service hijacking and sc stop to stop and reconfigure the COMSysApp.

T1574.011
Services Registry Permissions Weakness
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used a batch file that modified the COMSysApp service to load a malicious ipnet.dll payload and to load a DLL into the `svchost.exe` process.

T1583.001
Domains
CampaignOperation Honeybee

During Operation Honeybee, threat actors registered domains for C2.

T1583.004
Server
CampaignOperation Honeybee

For Operation Honeybee, at least one identified persona was used to register for a free account for a control server.

T1585.002
Email Accounts
CampaignOperation Honeybee

During Operation Honeybee, attackers created email addresses to register for a free account for a control server used for the implants.

T1588.004
Digital Certificates
CampaignOperation Honeybee

For Operation Honeybee, the threat actors stole a digital signature from Adobe Systems to use with their MaoCheng dropper.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.