
North Korean Linked Actor 'Void Banshee' Exploits Windows MHTML Zero-Day in Global Espionage Campaign
Void Banshee is exploiting CVE-2024-38112 to target global organizations. The campaign uses internet shortcut files to bypass security and deploy the Atlantida info-stealer malware.
Encrygma is selling the entire Full Cyber Weapon Research of North Korean Linked Actor 'Void Banshee' Exploits Windows MHTML Zero-Day in Global Espionage Campaign for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- State Cyber Warfare
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- High Confidence
- CVE:
- CVE-2024-38112
- Source:
- Trend Micro
- Read Time:
- 4 min
Executive Summary
On July 9, 2024, significant intelligence reports emerged detailing a sophisticated cyber-espionage campaign conducted by a threat actor tracked as 'Void Banshee'. This campaign is currently exploiting a recently disclosed zero-day vulnerability within the Windows MHTML engine, identified as CVE-2024-38112. This vulnerability allows attackers to bypass security features and execute arbitrary code on a victim's machine by manipulating the way Windows handles specific URI schemes. Encrygma has observed that this campaign is global in scope, targeting a wide array of sectors including government agencies, defense contractors, and telecommunications providers.
Threat Analysis
Void Banshee demonstrates a high level of operational maturity, focusing on initial access techniques that bypass standard security warnings. The group's strategy involves the use of lured content that appears to be legitimate, such as technical documentation or legal files. By targeting the MHTML vulnerability, Void Banshee effectively circumvents modern browser defenses, as the attack leverages legacy components that are still present in modern versions of Windows. This technique is particularly effective against organizations that maintain legacy software compatibility but have not adequately hardened their environments against older protocol handlers. The threat actor's primary objective appears to be the long-term collection of credentials and sensitive data to facilitate further lateral movement within compromised networks.
Technical Details
The infection chain is multi-staged and begins with the distribution of ZIP archives containing malicious .url (Internet Shortcut) files. These files are crafted to use the "mhtml:" URI scheme, pointing to a remote server controlled by the attacker. When a user opens the shortcut, Windows is forced to use the deprecated Internet Explorer engine to process the request, even on systems where Internet Explorer has been officially disabled. This bypasses the security zone restrictions typically enforced by Microsoft Edge or Google Chrome.
Once the connection is established, the remote server delivers an HTA (HTML Application) file. This HTA file contains obfuscated VBScript and JavaScript that, when executed via 'mshta.exe', performs a series of system checks to detect sandboxes or virtual machines. If the environment is deemed safe, the script downloads a password-protected ZIP containing the final payload. The payload is the 'Atlantida' stealer, a sophisticated piece of malware written in C++. Atlantida is designed to harvest a wide range of data, including system information, screenshots, and credentials from over 50 different applications. It specifically targets browser 'Local State' files to extract encryption keys for stored passwords. Furthermore, the malware uses the 'Donut' shellcode generator to inject its core logic into legitimate Windows processes like 'svchost.exe', significantly increasing its stealth profile.
Attribution Assessment
Intelligence from Trend Micro and Encrygma’s internal analysis points to Void Banshee as a likely North Korean-linked threat actor. The group’s TTPs show a high degree of overlap with the Lazarus Group (Hidden Cobra) and Kimusky. Specifically, the use of HTA files as a primary delivery mechanism and the infrastructure-level similarities—such as the use of compromised legitimate websites for payload hosting—are characteristic of Pyongyang's state-sponsored cyber operations. The actor's focus on information gathering from strategic sectors aligns with the Democratic People's Republic of Korea's (DPRK) known intelligence requirements.
Implications
The discovery of this campaign underscores the persistent danger posed by legacy software components in modern operating systems. Nation-state actors like Void Banshee are adept at finding and weaponizing these 'forgotten' attack surfaces. The global nature of this campaign suggests a coordinated effort to harvest large quantities of sensitive data that could be used for espionage, financial gain, or to support future destructive operations. Organizations must recognize that even if they have migrated to modern browsers, the underlying OS may still harbor exploitable legacy protocols.
Recommendations
Encrygma strongly advises immediate deployment of the Microsoft July 2024 Patch Tuesday updates, which contain the fix for CVE-2024-38112. Security administrators should also consider disabling the MHTML protocol handler via the registry if it is not required for business operations. Monitoring for anomalous 'mshta.exe' and 'cmd.exe' processes spawned by internet shortcuts is a critical detection step. Additionally, implementing "Attack Surface Reduction" (ASR) rules that block the creation of child processes from Office applications or the execution of potentially obfuscated scripts can mitigate the impact of the initial infection vector. Finally, organizations should enhance their monitoring of egress traffic to suspicious IP ranges and known command-and-control infrastructure associated with North Korean APTs.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

South Korean Financial Sector Hit by Coordinated Data Exfiltration Campaign

GopherWhisper APT Escalates Global Espionage Campaign Targeting Government Infrastructure

