Skip to main content
QUIETLYTIC
Campaign

Operation Honeybee

Campaign targeting humanitarian aid and inter-Korean affairs organizations from late 2017 through early 2018, initially in South Korea before expanding to six additional countries, assessed as likely Korean-speaking actors.

Threat Level
MEDIUM
Status
Resolved
Targets
Humanitarian aid and inter-Korean affairs organizations, South Korea, Vietnam, Singapore, Japan, Indonesia, Argentina, Canada

Overview

Operation Honeybee (MITRE ATT&CK ID C0006) was a campaign that targeted humanitarian aid and inter-Korean affairs organizations from at least late 2017 through early 2018, per MITRE’s campaign profile. MITRE documents the campaign as initially targeting South Korea before expanding to include Vietnam, Singapore, Japan, Indonesia, Argentina, and Canada. Per MITRE’s citations, security researchers assessed the threat actors were likely Korean speakers based on metadata found in both lure documents and executables, and named the campaign “Honeybee” after an author name discovered in malicious Word documents.

Timeline

Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window runs from August 2017 to February 2018.

Named actors and tools (per MITRE’s description vs. our relationship data)

MITRE’s description assesses the actors as “likely Korean speakers” without naming a specific tracked group. We confirmed this directly against MITRE’s raw published STIX bundle: every relationship object for this campaign is a technique/tool “uses” edge (SYSCON, Reg, Tasklist, Systeminfo, cmd) — there is no “attributed-to” edge to any group, consistent with MITRE never having named a specific tracked actor for this campaign in the first place.

What we don’t have

No named threat group is formally attributed to this campaign in either MITRE’s description or our relationship data — only a linguistic/metadata-based assessment of likely Korean-speaking operators. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle.

Frequently Asked Questions

What was Operation Honeybee? A campaign, per MITRE ATT&CK, targeting humanitarian aid and inter-Korean affairs organizations from August 2017 to February 2018, starting in South Korea and expanding to six other countries.

Where does the name “Honeybee” come from? Per MITRE’s description, from an author name discovered in the metadata of malicious Word documents used as lures.

Who conducted Operation Honeybee? MITRE’s description notes an assessment of likely Korean-speaking operators based on document/executable metadata — not a formally named or confirmed threat group.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0006, aggregated September 6, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Analyst tools