"The final payload of this zero-day attack chain is the Atlantida stealer, which was first discovered in January 2024."
Atlantida
Atlantida is a Windows information-stealing malware family first observed in 2024 and associated with financially motivated activity, including campaigns linked to the threat actor Void Banshee.
Profile source: Mallory opens in a new tabAtlantida
Family profile
Atlantida is a Windows information-stealing malware family first observed in 2024 and associated with financially motivated activity, including campaigns linked to the threat actor Void Banshee. It is designed to harvest a broad set of victim data, with emphasis on browser-stored credentials and session material, cryptocurrency wallet data, and other locally stored information of monetary or operational value.
Atlantida has been delivered through socially engineered execution chains in which a victim downloads and manually launches a malicious HTA file from a compromised website. Reported intrusion chains use script-based staging and in-memory loading, including VBScript and PowerShell, followed by a .NET downloader, shellcode execution, reflective loading, and remote thread injection into a legitimate Windows process to load the final payload without writing all stages to disk. This execution model indicates a strong focus on defense evasion and post-compromise stealth.
Once active, Atlantida targets data from major browsers including Chrome, Firefox, and Edge. It steals stored passwords, cookies, authentication tokens, payment-card data, and autofill information, and also enumerates Chrome-based browser extensions associated with cryptocurrency wallets. Beyond browsers, it has been reported to collect data from applications and stores such as Telegram, Steam, FileZilla, Binance-related local data, desktop text files, and offline cryptocurrency wallets. It also captures screenshots and gathers host profiling information such as CPU, GPU, RAM, and display characteristics before compressing and exfiltrating the collected data to attacker-controlled infrastructure.
Atlantida has been observed as the final payload in exploit chains involving Microsoft Windows vulnerabilities, including campaigns attributed to Void Banshee that used MSHTML-related flaws for delivery. Reported targeting spans North America, Europe, and Southeast Asia, with objectives centered on information theft and financial gain. Its combination of browser theft, wallet targeting, in-memory execution, and process injection places it among modern commodity and actor-operated stealers focused on credential access, session hijacking, and cryptocurrency theft.
Capabilities
- Credential Theft
- Crypto Theft
- Defense Evasion
- Exfiltration
- Process Injection
- Reconnaissance
- Session Hijacking
Reported operators
Threat actors
1 named in public reportingExploited software
Vulnerabilities linked to Atlantida
2 CVEsMITRE ATT&CK