Void Banshee APT Exploits Microsoft MHTML Flaw to Spread Atlantida Stealer
ID: 735a1783-2bdc-54d3-9cb5-ae06682eefaf
STIX ID: report--735a1783-2bdc-54d3-9cb5-ae06682eefaf
Feed Name: The Hacker News
Threat Score
Trend Micro reported that APT 'Void Banshee' exploited Microsoft MSHTML vulnerability CVE-2024-38112 as a zero-day to deliver the Atlantida info-stealer via spear-phishing ZIPs containing malicious .url files that lead to HTA -> VBS -> PowerShell -> .NET loader stages (using Donut shellcode to run in RegAsm.exe), with the stealer harvesting browser data, wallets and application credentials across multiple regions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
