Overview
Operation Honeybee (MITRE ATT&CK ID C0006) was a campaign that targeted humanitarian aid and inter-Korean affairs organizations from at least late 2017 through early 2018, per MITRE’s campaign profile. MITRE documents the campaign as initially targeting South Korea before expanding to include Vietnam, Singapore, Japan, Indonesia, Argentina, and Canada. Per MITRE’s citations, security researchers assessed the threat actors were likely Korean speakers based on metadata found in both lure documents and executables, and named the campaign “Honeybee” after an author name discovered in malicious Word documents.
Timeline
Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window runs from August 2017 to February 2018.
Named actors and tools (per MITRE’s description vs. our relationship data)
MITRE’s description assesses the actors as “likely Korean speakers” without naming a specific tracked group. We confirmed this directly against MITRE’s raw published STIX bundle: every relationship object for this campaign is a technique/tool “uses” edge (SYSCON, Reg, Tasklist, Systeminfo, cmd) — there is no “attributed-to” edge to any group, consistent with MITRE never having named a specific tracked actor for this campaign in the first place.
What we don’t have
No named threat group is formally attributed to this campaign in either MITRE’s description or our relationship data — only a linguistic/metadata-based assessment of likely Korean-speaking operators. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle.
Frequently Asked Questions
What was Operation Honeybee? A campaign, per MITRE ATT&CK, targeting humanitarian aid and inter-Korean affairs organizations from August 2017 to February 2018, starting in South Korea and expanding to six other countries.
Where does the name “Honeybee” come from? Per MITRE’s description, from an author name discovered in the metadata of malicious Word documents used as lures.
Who conducted Operation Honeybee? MITRE’s description notes an assessment of likely Korean-speaking operators based on document/executable metadata — not a formally named or confirmed threat group.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0006, aggregated September 6, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.