Cyber Security News

Hackers Exploiting MSHTML vulnerability to Deliver Atlantida Malware

Void Banshee, a threat actor, has been exploiting a critical MSHTML vulnerability, CVE-2024-38112, to distribute the Atlantida InfoStealer malware.

This sophisticated campaign has targeted unsuspecting users by attracting PDF books distributed via various public platforms, including online libraries and Discord servers.

The Exploit: CVE-2024-38112

CVE-2024-38112 is a vulnerability in MSHTML, Internet Explorer’s rendering engine. Despite Internet Explorer being disabled, attackers have found a way to abuse it. URL files to execute malicious code.

According to Broadcom report, this vulnerability has become a crucial vector for distributing the Atlantida InfoStealer, a malware designed to exfiltrate sensitive information from compromised systems.

Join our free webinar to learn about combating slow DDoS attacks, a major threat today.

The Attack Vector

Users are lured into downloading archives that supposedly contain PDF books. These archives are shared across multiple platforms, making them accessible to a broad audience. Once users download and open the archive, they are tricked into executing the Atlantida stealer.

This malware begins its nefarious activities, targeting login information from applications such as Telegram, Steam, various offline cryptocurrency wallets, and browser-stored data.

Void Banshee, the group behind this campaign, has been identified as a sophisticated threat actor with a history of deploying advanced malware.

Their latest campaign leveraging CVE-2024-38112 showcases their ability to exploit even the most obscure vulnerabilities to achieve their objectives.

All WebPulse-enabled products cover observed domains and IPs associated with this campaign under security categories, ensuring comprehensive web protection.

The exploitation of CVE-2024-38112 by Void Banshee to distribute Atlantida InfoStealer underscores the evolving nature of cyber threats. Users must remain vigilant and adopt robust security measures to protect their sensitive information.

Symantec’s comprehensive security solutions provide a formidable defense against such sophisticated attacks, ensuring that users can confidently navigate the digital landscape.

Protect Your Business Emails From Spoofing, Phishing & BEC with AI-Powered Security | Free Demo

Dhivya

Divya is a Senior Journalist at Cyber Security news covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago