Void Banshee APT Exploits Microsoft MHTML Flaw to Spread Atlantida Stealer
Briefly

Variations of the Atlantida campaign by Void Banshee use CVE-2024-38112, exploiting disabled services like Internet Explorer, posing a significant threat globally.
CVE-2024-38112, initially addressed in Patch Tuesday updates, is a spoofing vulnerability according to Microsoft, while ZDI considers it a remote code execution flaw.
Attack chains involve spear-phishing emails with links to ZIP files exploiting CVE-2024-38112, redirecting victims to compromised sites with malicious HTA files for execution.
Read at The Hacker News
[
|
]