Void Banshee is an APT group targeting North America, Europe, and Southeast Asia for information theft and financial gain. They exploit vulnerabilities like CVE-2024-38112 to deliver the Atlantida info-stealer through malicious PDFs disguised as book files. The group uses internet shortcuts with MHTML protocol handlers to access and execute files through disabled Internet Explorer, posing a significant threat to organizations. Void Banshee's TTPs include crafting URL strings to control window sizes in IE and using HTML files to hide malicious downloads from victims.
Executive Summary
Void Banshee is an advanced persistent threat (APT) group targeting North America, Europe, and Southeast Asia for information theft and financial gain. They exploit vulnerabilities like CVE-2024-38112 to deliver the Atlantida info-stealer via malicious PDFs. Their use of MHTML protocol handlers with disabled Internet Explorer poses a significant risk. The group's tactics include crafting URL strings to control window sizes in IE and leveraging HTML files for malicious downloads.
Goals & Targeting
Void Banshee targets regions with high economic activity, including North America, Europe, and Southeast Asia, where sensitive financial and personal data are more prevalent. They focus on sectors such as finance and technology, as well as individuals like high-net-worth people, due to the potential for significant financial gains through stolen information.
Enhanced Description
Void Banshee operates as an APT group primarily seeking financial gain and sensitive information through targeted attacks. Their activity involves the use of known vulnerabilities, such as CVE-2024-38112, to deliver their Atlantida info-stealer via malicious PDFs disguised as innocent book files. This vector is particularly dangerous due to its credibility in phishing campaigns, where victims are more likely to trust documents related to书籍. The group employies internet shortcuts using MHTML protocol handlers, exploiting older systems with disabled or outdated Internet Explorer settings. This technique allows them to execute arbitrary code on the victim's machine by bypassing certain security mechanisms. Additionally, Void Banshee's attackers craft URL strings to manipulate window sizing in IE, which further aids in controlling and concealing malicious activities during execution. Their operational methods indicate a sophisticated understanding of both technical vulnerabilities and human psychology to facilitate their attacks.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Void Banshee's campaigns are characterized by APT-like behavior, focusing on stealthy information theft and financial gains. Their targeting patterns suggest they focus on high-value individuals and businesses, likely to maximize their payout. The group uses sophisticated techniques such as exploit chaining and payload delivery mechanisms, which require significant technical expertise. Notable operations include the use of vulnerability exploitation for targeted attacks, as well as leveraging lesser-known protocols like MHTML for persistence.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis of Void Banshee is moderately confident, as the threat group's TTPs are well-documented and their targeting patterns are consistent across campaigns. However, specific details about campaign origins or exact attack counts remain gaps in intelligence, affecting precise impact assessment.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics