Void Banshee

Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:16:28

Targeted industries: financial-services technology-and-telecommunications government-and-public-sector

Targeted regions: country_code:us country_code:ca country_code:gb country_code:de country_code:fr country_code:sg

Context

Void Banshee is an APT group targeting North America, Europe, and Southeast Asia for information theft and financial gain. They exploit vulnerabilities like CVE-2024-38112 to deliver the Atlantida info-stealer through malicious PDFs disguised as book files. The group uses internet shortcuts with MHTML protocol handlers to access and execute files through disabled Internet Explorer, posing a significant threat to organizations. Void Banshee's TTPs include crafting URL strings to control window sizes in IE and using HTML files to hide malicious downloads from victims.

Exploited vulnerabilities

  • CVE-2024-38112 (vulnerability)

Reports & references

  • Trend Micro — Cve 2024 38112 Void Banshee (report)

Attributed from

  • Void Banshee Zero-Day Exploit Activity (campaign)

External references