Windows vulnerability abused braille “spaces” in zero-day attacks
ID: aaf38576-926c-5d1d-844c-98dc4906807c
STIX ID: report--aaf38576-926c-5d1d-844c-98dc4906807c
Feed Name: Bleeping Computer
**Executive summary:** Microsoft updated its advisory for CVE-2024-43461 after evidence showed the Void Banshee APT exploited the MSHTML vulnerability (together with CVE-2024-38112) to deliver Atlantida info-stealer via crafted .url and .hta files; attackers used repeated braille whitespace characters to conceal the .hta extension and socially engineer victims into executing the payload, resulting in credential, cookie, and cryptocurrency wallet theft. Microsoft has issued patches that mitigate showing the actual .hta extension in prompts, but the flaw was actively exploited in the wild prior to the fix.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
