Void Banshee
0 incidentes
0 paises
0 sectores
apt unknown Ultimo: -
Void Banshee is a financially motivated advanced persistent threat group first observed in mid-2024, distinguished by its unique approach to exploiting Microsoft Windows MSHTML vulnerabilities. The group's primary objective is credential theft and financial gain, achieved through targeted campaigns that leverage a 'zombie' Internet Explorer process and unsupported Windows components. This allows them to bypass modern security sandboxes and deliver information-stealing malware stealthily. Their method involves specially crafted internet shortcut files and MHTML protocol handlers, often disguised as legitimate documents, a tactic that sets them apart from other groups by weaponizing outdated system relics for contemporary attacks.
Sectores objetivo (SOCRadar)
Professional&Technical ServicesEducational ServicesData Processing, Hosting, and Related ServicesComputer Systems Design and Related Services