News Room
16
Share
Void Banshee APT Exploits Microsoft MHTML Zero-Day (CVE-2024-38112) in Global Espionage Campaign
highCyber Espionage

Void Banshee APT Exploits Microsoft MHTML Zero-Day (CVE-2024-38112) in Global Espionage Campaign

A sophisticated espionage campaign by the 'Void Banshee' APT group leverages a zero-day vulnerability in Windows MHTML. The operation targets organizations globally using malicious shortcuts to steal data.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Void Banshee APT Exploits Microsoft MHTML Zero-Day (CVE-2024-38112) in Global Espionage Campaign for ₿ 0.10 BTC. Contact us.

09 July 2026Last updated 20 August 20264 min readCheck Point Research
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
High
Actor Type:
APT
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2024-38112
Source:
Check Point Research
Read Time:
4 min

Executive Summary\n\nRecent intelligence reports from Check Point Research have uncovered a sophisticated cyber espionage campaign conducted by the threat actor known as Void Banshee. This campaign exploits a previously unknown zero-day vulnerability in the Microsoft Windows MHTML engine, tracked as CVE-2024-38112. The actors target organizations across North America, Europe, and Southeast Asia, aiming to exfiltrate sensitive information through a highly targeted infection chain. The operation highlights the persistent risk posed by legacy browser components within modern operating systems, which can be weaponized to bypass contemporary security perimeters.\n\n## Threat Analysis\n\nVoid Banshee focuses on high-value targets, including government entities and commercial enterprises involved in regional geopolitics. The campaign begins with the distribution of zip files containing malicious internet shortcut (.URL) files. These shortcuts are often disguised as legitimate documents, such as PDF versions of regional regulations, clinical trial data, or professional resumes. When a victim opens the file, the campaign initiates a multi-stage infection process designed to bypass traditional security controls and establish long-term persistence within the target network. The group demonstrates a high level of technical proficiency in identifying and exploiting obscure attack vectors that remain overlooked by standard patch management cycles.\n\n## Technical Details\n\nThe core of the operation lies in the exploitation of CVE-2024-38112. The malicious .URL files utilize the 'ms-its:' protocol handler, which forces the system to process the request using the deprecated Internet Explorer MHTML engine. By leveraging this vulnerability, Void Banshee can execute arbitrary code even if Internet Explorer is disabled as a standalone browser on the system. Once triggered, the exploit downloads an HTML file that executes a PowerShell script. This script, in turn, fetches the final payload—a variant of the 'Atlantida' infostealer. Atlantida is capable of harvesting credentials from browsers, stealing system information, and capturing sensitive files from the victim's local storage and clipboard, providing the actors with comprehensive access to the victim's digital footprint.\n\n## Attribution Assessment\n\nAnalysis of the tactics, techniques, and procedures (TTPs) strongly suggests the involvement of Void Banshee, an APT group with history targeting North American and Asian entities. The group's methodology—specifically the use of internet shortcuts and the targeting of specific regional document formats—aligns with previous operations observed by threat intelligence researchers. While the group shows some overlaps with other known clusters, the specific combination of the MHTML zero-day and the Atlantida stealer is currently unique to this threat actor's toolkit. Confidence in this attribution is high, based on infrastructure reuse, victimology, and unique code signatures in the delivery stage.\n\n## Implications\n\nThe success of this campaign demonstrates that legacy Windows features remain a significant attack surface for nation-state actors. The ability to force modern Windows 11 systems to utilize insecure components of Internet Explorer allows attackers to circumvent modern web security protections like Mark-of-the-Web (MoTW) and SmartScreen in some configurations. For organizations, this represents a critical risk where an unsuspecting click on a seemingly benign shortcut can lead to full system compromise and massive data exfiltration, potentially impacting national security, intellectual property, and competitive trade secrets.\n\n## Recommendations\n\nTo mitigate the risk of Void Banshee and similar threats, organizations should immediately apply the security updates released by Microsoft for July 2024, which address CVE-2024-38112. Additionally, security teams should implement stricter controls on the execution of .URL files and monitor for unusual activity associated with the 'ms-its:' protocol. Disabling or restricting the MHTML protocol via Group Policy and enhancing user training regarding the dangers of opening unsolicited shortcut files are also critical steps. Finally, deploying advanced endpoint detection and response (EDR) solutions can help identify the execution of suspicious PowerShell scripts and the deployment of infostealer payloads.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo