MaoCheng is a Win32 executable dropper associated with Operation Honeybee. McAfee identified it during that campaign as a signed dropper used alongside malicious Microsoft Word lure documents targeting humanitarian aid organizations, with observed targeting and submissions indicating activity in Vietnam and South Korea and additional victim geographies including Singapore, Argentina, Japan, Indonesia, and Canada. The dropper was signed with a stolen Adobe Systems digital signature and was modified so its icon appeared as a Word document, indicating both code-signing abuse and masquerading for defense evasion and user deception. Content also notes a related Korean-language sample compiled on January 16 with SHA-1 35904f482d37f5ce6034d6042bae207418e450f4 and a PDB path referencing "DDE Attack\MaoCheng\Release\Dropper.pdb." MaoCheng masqueraded as a Word document, used a Xero-themed decoy, and dropped the same malware family delivered by the campaign’s malicious Word documents. McAfee assessed the dropper contained a bug that interfered with execution, suggesting inadequate testing after code signing. High-confidence behaviors directly described in the content are that MaoCheng functioned as a dropper, used a stolen Adobe certificate, displayed a Word-document icon, and delivered the same malware family used elsewhere in Operation Honeybee.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MaoCheng is a dropper signed with a stolen Adobe Systems digital signature.
A Win32 executable dropper (signed with a stolen Adobe Systems certificate) that masquerades as a Word document and drops the same SYSCON-related implant chain seen in the malicious Word documents, including a decoy document and components used to install a service-based DLL for persistence/execution.
A code-signed dropper used in Operation Honeybee; it was modified to masquerade as a Word document and was signed using a stolen Adobe Systems digital signature to help evade trust controls and facilitate execution.
Dropper that can be modified to masquerade as benign documents (e.g., Word icon) to increase execution success.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.