logo

Void Banshee APT Exploits Microsoft Zero-Day in Spear-Phishing Attacks

ID: a77479a2-cf23-59e8-bf43-fcc605fbe254

STIX ID: report--a77479a2-cf23-59e8-bf43-fcc605fbe254

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-07-16

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Trend Micro researchers detail how the APT known as Void Banshee exploited an MSHTML/Internet Explorer zero-day (CVE-2024-38112) via spear-phishing URL-shortcut files disguised as PDFs to run HTA stages and deliver the Atlantida stealer; the malware harvests passwords, cookies, application data, and screenshots and exfiltrates data to attacker-controlled C2 over TCP 6655. The campaign targeted victims across North America, Europe, and Southeast Asia, abused legacy IE functionality even when IE was disabled, and includes IoCs and recommended mitigations (apply Microsoft's patch, monitor assets, and adopt advanced threat intelligence).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.