Honeybee is a malware family and intrusion set associated with document-based initial access and service-based execution on Windows systems. It has been observed using malicious Microsoft Word documents containing embedded Visual Basic script or macros to decode and drop an additional payload, including Base64-encoded content, when the document is opened. The malware then uses batch scripting and Windows service manipulation to launch a DLL under svchost.exe and to establish persistence by configuring a service to autostart. Honeybee also modifies the Windows Registry as part of its execution and persistence workflow. Post-compromise, Honeybee performs host reconnaissance and collection. It gathers system information such as computer name and host details using native commands including systeminfo, and enumerates running processes using tasklist before sending the results to its command-and-control infrastructure. It also collects data from the local victim system and includes functionality to traverse accessible FTP directories in search of files matching selected keywords, indicating targeted file discovery and collection behavior. Operationally, Honeybee supports multiple commands through a command-line interface and includes the ability to execute arbitrary custom commands on infected endpoints. The malware also demonstrates anti-forensics and cleanup behavior by deleting batch files and other temporary artifacts after infection to reduce its footprint. Overall, Honeybee combines phishing-based delivery, script-driven payload staging, service-based persistence, host discovery, file collection, and artifact cleanup in support of espionage-oriented intrusion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Traversed FTP server directories to locate files matching computer names or selected keywords.
Uses systeminfo to gather computer name and other host information.
Uses malicious Word documents and macros to decode embedded Base64 payloads and drop them to disk.
Uses a batch file to configure an autostart service for persistence.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.