Void Banshee is an APT group using CVE-2024-38112 and Atlantida info-stealer for information theft.
Analyst brief
Void Banshee is an APT group operating in North America, Europe, and Southeast Asia, focused on information theft and financial gain. They target organizations, utilizing CVE-2024-38112 to deliver the Atlantida info-stealer through malicious PDFs disguised as book files. Their TTPs include using internet shortcuts with MHTML protocol handlers to execute files via a disabled Internet Explorer, crafting URL strings to control IE window sizes, and using HTML files to hide malicious downloads. Defenders should monitor for exploitation of vulnerabilities like CVE-2024-38112, suspicious PDFs, MHTML protocol usage in shortcuts, and unexpected Internet Explorer process execution.
Void Banshee
unknown
Void Banshee is an APT group targeting North America, Europe, and Southeast Asia for information theft and financial gain. They exploit vulnerabilities like CVE-2024-38112 to deliver the Atlantida info-stealer through malicious PDFs disguised as book files. The group uses internet shortcuts with MHTML protocol handlers to access and execute files through disabled Internet Explorer, posing a significant threat to organizations. Void Banshee's TTPs include crafting URL strings to control window sizes in IE and using HTML files to hide malicious downloads from victims.