logo

Void Banshee APT Exploits Microsoft MHTML Flaw to Spread Atlantida Stealer

ID: 735a1783-2bdc-54d3-9cb5-ae06682eefaf

STIX ID: report--735a1783-2bdc-54d3-9cb5-ae06682eefaf

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-07-16

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Trend Micro reported that APT 'Void Banshee' exploited Microsoft MSHTML vulnerability CVE-2024-38112 as a zero-day to deliver the Atlantida info-stealer via spear-phishing ZIPs containing malicious .url files that lead to HTA -> VBS -> PowerShell -> .NET loader stages (using Donut shellcode to run in RegAsm.exe), with the stealer harvesting browser data, wallets and application credentials across multiple regions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.