Last seven days
- First activity
- Aug 21, 2026
- Last activity
- Aug 21, 2026
- Feed role
- C2
- Host form
- 2 IP / 0 hostnames
Atlantida is a Windows information-stealing malware family first observed in 2024 and associated with financially motivated activity, including campaigns linked to the threat actor Void Banshee.
Profile source: Mallory opens in a new tabAtlantida
Atlantida is a Windows information-stealing malware family first observed in 2024 and associated with financially motivated activity, including campaigns linked to the threat actor Void Banshee. It is designed to harvest a broad set of victim data, with emphasis on browser-stored credentials and session material, cryptocurrency wallet data, and other locally stored information of monetary or operational value.
Atlantida has been delivered through socially engineered execution chains in which a victim downloads and manually launches a malicious HTA file from a compromised website. Reported intrusion chains use script-based staging and in-memory loading, including VBScript and PowerShell, followed by a .NET downloader, shellcode execution, reflective loading, and remote thread injection into a legitimate Windows process to load the final payload without writing all stages to disk. This execution model indicates a strong focus on defense evasion and post-compromise stealth.
Once active, Atlantida targets data from major browsers including Chrome, Firefox, and Edge. It steals stored passwords, cookies, authentication tokens, payment-card data, and autofill information, and also enumerates Chrome-based browser extensions associated with cryptocurrency wallets. Beyond browsers, it has been reported to collect data from applications and stores such as Telegram, Steam, FileZilla, Binance-related local data, desktop text files, and offline cryptocurrency wallets. It also captures screenshots and gathers host profiling information such as CPU, GPU, RAM, and display characteristics before compressing and exfiltrating the collected data to attacker-controlled infrastructure.
Atlantida has been observed as the final payload in exploit chains involving Microsoft Windows vulnerabilities, including campaigns attributed to Void Banshee that used MSHTML-related flaws for delivery. Reported targeting spans North America, Europe, and Southeast Asia, with objectives centered on information theft and financial gain. Its combination of browser theft, wallet targeting, in-memory execution, and process injection places it among modern commodity and actor-operated stealers focused on credential access, session hijacking, and cryptocurrency theft.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
"The final payload of this zero-day attack chain is the Atlantida stealer, which was first discovered in January 2024."
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.