News Room
16
Share
North Korean Linked Actor 'Void Banshee' Exploits Windows MHTML Zero-Day in Global Espionage Campaign
criticalState Cyber Warfare

North Korean Linked Actor 'Void Banshee' Exploits Windows MHTML Zero-Day in Global Espionage Campaign

Void Banshee is exploiting CVE-2024-38112 to target global organizations. The campaign uses internet shortcut files to bypass security and deploy the Atlantida info-stealer malware.

₿

Encrygma is selling the entire Full Cyber Weapon Research of North Korean Linked Actor 'Void Banshee' Exploits Windows MHTML Zero-Day in Global Espionage Campaign for ₿ 0.10 BTC. Contact us.

09 July 2026Last updated 20 August 20264 min readTrend Micro
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
State Cyber Warfare
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2024-38112
Source:
Trend Micro
Read Time:
4 min

Executive Summary

On July 9, 2024, significant intelligence reports emerged detailing a sophisticated cyber-espionage campaign conducted by a threat actor tracked as 'Void Banshee'. This campaign is currently exploiting a recently disclosed zero-day vulnerability within the Windows MHTML engine, identified as CVE-2024-38112. This vulnerability allows attackers to bypass security features and execute arbitrary code on a victim's machine by manipulating the way Windows handles specific URI schemes. Encrygma has observed that this campaign is global in scope, targeting a wide array of sectors including government agencies, defense contractors, and telecommunications providers.

Threat Analysis

Void Banshee demonstrates a high level of operational maturity, focusing on initial access techniques that bypass standard security warnings. The group's strategy involves the use of lured content that appears to be legitimate, such as technical documentation or legal files. By targeting the MHTML vulnerability, Void Banshee effectively circumvents modern browser defenses, as the attack leverages legacy components that are still present in modern versions of Windows. This technique is particularly effective against organizations that maintain legacy software compatibility but have not adequately hardened their environments against older protocol handlers. The threat actor's primary objective appears to be the long-term collection of credentials and sensitive data to facilitate further lateral movement within compromised networks.

Technical Details

The infection chain is multi-staged and begins with the distribution of ZIP archives containing malicious .url (Internet Shortcut) files. These files are crafted to use the "mhtml:" URI scheme, pointing to a remote server controlled by the attacker. When a user opens the shortcut, Windows is forced to use the deprecated Internet Explorer engine to process the request, even on systems where Internet Explorer has been officially disabled. This bypasses the security zone restrictions typically enforced by Microsoft Edge or Google Chrome.

Once the connection is established, the remote server delivers an HTA (HTML Application) file. This HTA file contains obfuscated VBScript and JavaScript that, when executed via 'mshta.exe', performs a series of system checks to detect sandboxes or virtual machines. If the environment is deemed safe, the script downloads a password-protected ZIP containing the final payload. The payload is the 'Atlantida' stealer, a sophisticated piece of malware written in C++. Atlantida is designed to harvest a wide range of data, including system information, screenshots, and credentials from over 50 different applications. It specifically targets browser 'Local State' files to extract encryption keys for stored passwords. Furthermore, the malware uses the 'Donut' shellcode generator to inject its core logic into legitimate Windows processes like 'svchost.exe', significantly increasing its stealth profile.

Attribution Assessment

Intelligence from Trend Micro and Encrygma’s internal analysis points to Void Banshee as a likely North Korean-linked threat actor. The group’s TTPs show a high degree of overlap with the Lazarus Group (Hidden Cobra) and Kimusky. Specifically, the use of HTA files as a primary delivery mechanism and the infrastructure-level similarities—such as the use of compromised legitimate websites for payload hosting—are characteristic of Pyongyang's state-sponsored cyber operations. The actor's focus on information gathering from strategic sectors aligns with the Democratic People's Republic of Korea's (DPRK) known intelligence requirements.

Implications

The discovery of this campaign underscores the persistent danger posed by legacy software components in modern operating systems. Nation-state actors like Void Banshee are adept at finding and weaponizing these 'forgotten' attack surfaces. The global nature of this campaign suggests a coordinated effort to harvest large quantities of sensitive data that could be used for espionage, financial gain, or to support future destructive operations. Organizations must recognize that even if they have migrated to modern browsers, the underlying OS may still harbor exploitable legacy protocols.

Recommendations

Encrygma strongly advises immediate deployment of the Microsoft July 2024 Patch Tuesday updates, which contain the fix for CVE-2024-38112. Security administrators should also consider disabling the MHTML protocol handler via the registry if it is not required for business operations. Monitoring for anomalous 'mshta.exe' and 'cmd.exe' processes spawned by internet shortcuts is a critical detection step. Additionally, implementing "Attack Surface Reduction" (ASR) rules that block the creation of child processes from Office applications or the execution of potentially obfuscated scripts can mitigate the impact of the initial infection vector. Finally, organizations should enhance their monitoring of egress traffic to suspicious IP ranges and known command-and-control infrastructure associated with North Korean APTs.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo