Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Void Banshee

Description

Void Banshee is an APT group targeting North America, Europe, and Southeast Asia for information theft and financial gain. They exploit vulnerabilities like CVE-2024-38112 to deliver the Atlantida info-stealer through malicious PDFs disguised as book files. The group uses internet shortcuts with MHTML protocol handlers to access and execute files through disabled Internet Explorer, posing a significant threat to organizations. Void Banshee's TTPs include crafting URL strings to control window sizes in IE and using HTML files to hide malicious downloads from victims.

AI Analysis

· 1 week ago

Executive Summary

Void Banshee is an advanced persistent threat (APT) group targeting North America, Europe, and Southeast Asia for information theft and financial gain. They exploit vulnerabilities like CVE-2024-38112 to deliver the Atlantida info-stealer via malicious PDFs. Their use of MHTML protocol handlers with disabled Internet Explorer poses a significant risk. The group's tactics include crafting URL strings to control window sizes in IE and leveraging HTML files for malicious downloads.

Goals & Targeting

Void Banshee targets regions with high economic activity, including North America, Europe, and Southeast Asia, where sensitive financial and personal data are more prevalent. They focus on sectors such as finance and technology, as well as individuals like high-net-worth people, due to the potential for significant financial gains through stolen information.

Enhanced Description

Void Banshee operates as an APT group primarily seeking financial gain and sensitive information through targeted attacks. Their activity involves the use of known vulnerabilities, such as CVE-2024-38112, to deliver their Atlantida info-stealer via malicious PDFs disguised as innocent book files. This vector is particularly dangerous due to its credibility in phishing campaigns, where victims are more likely to trust documents related to书籍. The group employies internet shortcuts using MHTML protocol handlers, exploiting older systems with disabled or outdated Internet Explorer settings. This technique allows them to execute arbitrary code on the victim's machine by bypassing certain security mechanisms. Additionally, Void Banshee's attackers craft URL strings to manipulate window sizing in IE, which further aids in controlling and concealing malicious activities during execution. Their operational methods indicate a sophisticated understanding of both technical vulnerabilities and human psychology to facilitate their attacks.

Key Capabilities

  • Exploits known vulnerabilities (e.g., CVE-2024-38112)
  • Deploy Atlantida info-stealer via malicious PDFs
  • Uses MHTML protocol handlers with disabled Internet Explorer
  • Crafts URL strings to control window sizing in IE for execution
  • Leverages HTML files to mask malicious downloads

MITRE ATT&CK Tactics

Initial Access
Execution
Payload Delivery
Defense Evasion

ATT&CK Techniques

T1566.002
T1055
T1197.x
T1486.002

Software / Tooling

Atlantida info-stealer

Campaigns & Victims

Void Banshee's campaigns are characterized by APT-like behavior, focusing on stealthy information theft and financial gains. Their targeting patterns suggest they focus on high-value individuals and businesses, likely to maximize their payout. The group uses sophisticated techniques such as exploit chaining and payload delivery mechanisms, which require significant technical expertise. Notable operations include the use of vulnerability exploitation for targeted attacks, as well as leveraging lesser-known protocols like MHTML for persistence.

IOC Patterns

  • Spear-phishing with malicious PDFs
  • Exploitation via MHTML protocol handlers
  • URL string manipulation for window control

Recommended Actions

  • Patch systems against known vulnerabilities, including CVE-2024-38112.
  • Disable or remove Internet Explorer from older systems to mitigate MHTML exploitation risks.
  • Educate users on recognizing phishing attempts and suspicious file downloads.
  • Monitor network traffic for signs of malicious URL patterns linked to their TTPs.
  • Implement robust anti-malware solutions to detect known info-stealers like Atlantida.

Suggested Tags

APT
Info-Stealing
Financial Espionage

Confidence Assessment

The analysis of Void Banshee is moderately confident, as the threat group's TTPs are well-documented and their targeting patterns are consistent across campaigns. However, specific details about campaign origins or exact attack counts remain gaps in intelligence, affecting precise impact assessment.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Info-Stealing
Financial Espionage

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.