Honeybee (G0072) targets humanitarian aid organizations with malicious Word documents using North Korean political lures.
Analyst brief
Honeybee (G0072) is a threat operation targeting humanitarian aid organizations, using North Korean political topics as bait in malicious Microsoft Word documents. They have recently shifted tactics to using Word compatibility messages to lure victims into opening infected files. Defenders should focus on detecting and blocking suspicious Word documents, particularly those with political lures or compatibility prompts, and enforce strict macro execution policies.
Honeybee
G0072
unknown
McAfee Advanced Threat Research analysts have discovered a new operation targeting humanitarian aid organizations and using North Korean political topics as bait to lure victims into opening malicious Microsoft Word documents. Our analysts have named this Operation Honeybee, based on the names of the malicious documents used in the attacks.
Advanced Threat Research analysts have also discovered malicious documents authored by the same actor that indicate a tactical shift. These documents do not contain the typical lures by this actor, instead using Word compatibility messages to entice victims into opening them.
The Advanced Threat Research team also observed a heavy concentration of the implant in Vietnam from January 15–17.