Void Banshee
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:16:28
Targeted industries: financial-services technology-and-telecommunications government-and-public-sector
Targeted regions: country_code:us country_code:ca country_code:gb country_code:de country_code:fr country_code:sg
Context
Void Banshee is an APT group targeting North America, Europe, and Southeast Asia for information theft and financial gain. They exploit vulnerabilities like CVE-2024-38112 to deliver the Atlantida info-stealer through malicious PDFs disguised as book files. The group uses internet shortcuts with MHTML protocol handlers to access and execute files through disabled Internet Explorer, posing a significant threat to organizations. Void Banshee's TTPs include crafting URL strings to control window sizes in IE and using HTML files to hide malicious downloads from victims.
Exploited vulnerabilities
- CVE-2024-38112 (vulnerability)
Reports & references
- Trend Micro — Cve 2024 38112 Void Banshee (report)
Attributed from
- Void Banshee Zero-Day Exploit Activity (campaign)