Honeybee is a Windows malware implant associated with service-based execution and document-borne infection chains. It has been observed arriving through a malicious Microsoft Word document containing a Base64-encoded payload that is decoded and written to disk by a macro, after which batch-script logic modifies the Windows Registry to launch a DLL through svchost.exe as a service. The malware uses command-line and scripting components during installation and cleanup, including removal of staging artifacts to reduce forensic visibility.
Once active, Honeybee supports post-compromise command execution through a command-line interface and can run custom commands on infected endpoints. It performs host reconnaissance by enumerating running processes with tasklist and returning the results to its control infrastructure. For data theft, Honeybee collects files from the victim, stages them into a ZIP archive in temporary storage, Base64-encodes the archive, and uploads it to its command-and-control server. Its observed behavior indicates a combination of persistence, defense evasion, reconnaissance, command execution, and exfiltration capabilities focused on Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Honeybee launches a DLL file that gets executed as a service using svchost.exe
4 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information. | Multiple entries explicitly state use of the Windows systeminfo command, e.g., 'BlackEnergy has used Systeminfo to gather the OS version...' and 'OilRig has run hostname and systeminfo on a victim.'
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that uses a macro to decode and drop a Base64-encoded embedded file to disk.
Backdoor that enumerates processes via tasklist and exfiltrates results to C2.
Implant/tooling that supports command execution via a command-line interface; also uses batch scripting.
Malware that stages data into a ZIP in %temp%, Base64-encodes it, and uploads it to a control server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.