Operation Honeybee is a named intrusion campaign associated with post-compromise host reconnaissance, privilege escalation through User Account Control bypass, file discovery, command-and-control infrastructure setup, and defense-evasion through masquerading. Reported tradecraft includes collecting victim host details such as computer name and operating system information, searching local files for specific keywords, and registering command-and-control domains to support the operation. The campaign also used a malicious DLL together with a legitimate executable to bypass UAC protections, indicating an emphasis on obtaining elevated execution on compromised Windows systems. Additional observed behavior includes modifying a dropper so that it appeared to be a benign document, reflecting the use of masquerading to improve execution success and reduce suspicion. Based on the supplied facts, Operation Honeybee is best characterized as a targeted intrusion campaign with capabilities spanning reconnaissance, privilege escalation, defense evasion, and post-exploitation activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign in which operators used cmd and systeminfo to collect computer name, OS, and other system details.
Campaign involving UAC bypass using a malicious DLL and cliconfig.exe.
Campaign used a malicious DLL to search for files containing specific keywords.
Operation involving collection of computer name and OS details using systeminfo redirected to a temp file.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.