Uptime Hamster: 10d 18h 0mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Void Banshee

Void Banshee

0 incidentes 0 paises 0 sectores apt unknown Ultimo: -
Ver en IntelTracker → APTTrail →
Void Banshee is a financially motivated advanced persistent threat group first observed in mid-2024, distinguished by its unique approach to exploiting Microsoft Windows MSHTML vulnerabilities. The group's primary objective is credential theft and financial gain, achieved through targeted campaigns that leverage a 'zombie' Internet Explorer process and unsupported Windows components. This allows them to bypass modern security sandboxes and deliver information-stealing malware stealthily. Their method involves specially crafted internet shortcut files and MHTML protocol handlers, often disguised as legitimate documents, a tactic that sets them apart from other groups by weaponizing outdated system relics for contemporary attacks.

Actores similares

void-balauractor · 1Void Blizzardapt · 0Void Arachneapt · 0Void Rabisuapt · 0Void Manticoreapt · 0Void Balaurapt · 0SHADOW-VOID-042apt · 0VoidCryptransomware · 0
Tecnicas MITRE
T1113 - Screen Capture, T1547 - Boot or Logon Autostart Execution, T1027 - Obfuscated Files or Information, T1082 - System Information Discovery, T1555 - Credentials from Password Stores, T1218 - Signed Binary Proxy Execution
CVEs relacionadas
CVE-2024-6197, CVE-2024-43583, CVE-2024-43582, CVE-2024-43573, CVE-2024-43572, CVE-2024-43488
Tipo
apt
Pais origen
unknown
Motivacion
-
Impacto
35
Actualizado
Mon, 05 Ja

Sectores objetivo (SOCRadar)

Professional&Technical ServicesEducational ServicesData Processing, Hosting, and Related ServicesComputer Systems Design and Related Services