Target Industry 

Indiscriminate, opportunistic targeting.  

Overview 

A recently patched “Windows MSHTML spoofing vulnerability,” identified as CVE-2024-43461, has been confirmed as exploited by the Void Banshee APT hacking group. Initially disclosed during the September 2024 Patch Tuesday, Microsoft did not mark the vulnerability as previously exploited. However, an update to the CVE-2024-43461 advisory on Friday, September 13th, 2024 revealed its exploitation before the patch. 

Impact 

If successfully exploited, this vulnerability could result in a substantial compromise of the affected system. An attacker may gain unauthorised access to sensitive information, modify, or delete data, and disrupt system availability. Given its high impact on confidentiality, integrity, and availability, successful exploitation could lead to data breaches, system manipulation, and service interruptions.  

CVE-2024-43461 has been exploited in attacks by Void Banshee to install information stealing malware. The stealer primarily targets and extracts browser data, including credentials, browsing history, and cookies. 

Vulnerability Detection  

Microsoft has released a security update addressing the security flaw in the respective product versions. As such, previous versions are vulnerable to potential exploits.  

Exploitation 

The attackers employed specially crafted Windows Internet Shortcut files, identifiable by their .url extension. When a user clicks on one of these files, it triggers the retired Internet Explorer (IE) to navigate to a URL under the attacker’s control. This method takes advantage of legacy behaviours in the Windows operating system, leveraging Internet Explorer’s outdated but still present capabilities to bypass modern security measures. Furthermore, the use of these .url files allows the attackers to execute malicious payloads with minimal user interaction, often leading to the download and installation of malware such as the Atlantida info-stealer. 

Containment, Mitigations & Remediations 

Microsoft has released an official fix for this vulnerability on September 10th, 2024. It is highly recommended that all organisations run the relevant patches as soon as possible. 

Indicators of Compromise 

No indicators of compromise (IoCs) are available currently. 

Threat Landscape 

Windows is used on many devices all over the world as it is one of the main operating systems organisations use. Many devices have not run the latest security update this leaves them open to exploitation by threat actors to view and exfiltrate sensitive data. 

Threat Group 

Void Banshee is an Advanced Persistent Threat (APT) group primarily targeting North America, Europe, and Southeast Asia for information theft and financial gain. The group exploits vulnerabilities such as CVE-2024-38112 to deliver the Atlantida info-stealer via malicious PDFs disguised as eBooks. 

The group employs internet shortcuts with MHTML protocol handlers to access and execute files through a disabled Internet Explorer, posing a significant risk to organisations. Their tactics, techniques, and procedures (TTPs) include crafting URL strings to manipulate window sizes in Internet Explorer and using HTML files to conceal malicious downloads from unsuspecting victims. 

Further Information 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content