Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Campaigns/C0006
MITRE ATT&CK Campaign · 2017–2018

Operation Honeybee (C0006)

ShareXLinkedInRedditHN

[Operation Honeybee](https://attack.mitre.org/campaigns/C0006) was a campaign that targeted humanitarian aid and inter-Korean affairs organizations from at least late 2017 through early 2018. [Operation Honeybee](https://attack.mitre.org/campaigns/C0006) initially targeted South Korea, but expanded to include Vietnam, Singapore, Japan, Indonesia, Argentina, and Canada. Security researchers assessed the threat actors were likely Korean speakers based on metadata used in both lure documents and executables, and named the campaign "Honeybee" after the author name discovered in malicious Word documents.(Citation: McAfee Honeybee)

▪Techniques used (28)

T1585.002Email AccountsT1083File and Directory DiscoveryT1106Native APIT1070.004File DeletionT1074.001Local Data StagingT1583.001DomainsT1027.013Encrypted/Encoded FileT1553.002Code SigningT1041Exfiltration Over C2 ChannelT1112Modify RegistryT1059.003Windows Command ShellT1082System Information DiscoveryT1569.002Service ExecutionT1560.001Archive via UtilityT1574.011Services Registry Permissions WeaknessT1588.004Digital CertificatesT1071.002File Transfer ProtocolsT1548.002Bypass User Account ControlT1005Data from Local SystemT1543.003Windows ServiceT1583.004ServerT1036.005Match Legitimate Resource Name or LocationT1204.002Malicious FileT1105Ingress Tool TransferT1059.005Visual BasicT1057Process DiscoveryT1140Deobfuscate/Decode Files or InformationT1036Masquerading

▪Software used (5)

S0464SYSCONmalwareS0075RegtoolS0057TasklisttoolS0096SysteminfotoolS0106cmdtool
C0006on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.