Void Banshee APT Exploits Microsoft Zero-Day in Spear-Phishing Attacks
ID: a77479a2-cf23-59e8-bf43-fcc605fbe254
STIX ID: report--a77479a2-cf23-59e8-bf43-fcc605fbe254
Feed Name: Dark Reading
Date Published: 2024-07-16
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Trend Micro researchers detail how the APT known as Void Banshee exploited an MSHTML/Internet Explorer zero-day (CVE-2024-38112) via spear-phishing URL-shortcut files disguised as PDFs to run HTA stages and deliver the Atlantida stealer; the malware harvests passwords, cookies, application data, and screenshots and exfiltrates data to attacker-controlled C2 over TCP 6655. The campaign targeted victims across North America, Europe, and Southeast Asia, abused legacy IE functionality even when IE was disabled, and includes IoCs and recommended mitigations (apply Microsoft's patch, monitor assets, and adopt advanced threat intelligence).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
