The final payload of this zero-day attack chain is the Atlantida stealer, which was first discovered in January 2024. Variations of the Atlantida campaign have been highly active throughout 2024 and have evolved to use CVE-2024-38112 as part of Void Banshee infection chains.
Atlantida
Atlantida is a Windows information stealer first identified in January 2024 and associated with Void Banshee activity.
Profile source: Mallory opens in a new tabAtlantida
Family profile
Atlantida is a Windows information stealer first identified in January 2024 and associated with Void Banshee activity. It has been deployed in infection chains exploiting Windows MSHTML vulnerabilities, including CVE-2024-38112 and CVE-2024-43461, against targets in North America, Europe, and Southeast Asia. A separate observed delivery chain used a malicious HTA application obtained from a compromised website and executed by the victim. The chain uses script-based execution, PowerShell, reflective loading, shellcode, and remote-thread injection to execute the final payload in memory.
Atlantida collects credentials, cookies, authentication tokens, payment-card and autofill data from Chrome, Firefox, and Edge. It also targets cryptocurrency-wallet browser extensions and offline wallet data, and collects data associated with FileZilla, Steam, Binance, Telegram, and desktop text files. The stealer captures screenshots and gathers host hardware details, including processor, graphics, memory, and display information. Collected data is compressed and transmitted to command-and-control infrastructure. Atlantida’s theft of browser authentication material, cryptocurrency-wallet data, and financial-service artifacts supports both account compromise and cryptocurrency theft.
Capabilities
- Credential Theft
- Crypto Theft
- Defense Evasion
- Exfiltration
- Process Injection
- Reconnaissance
- Session Hijacking
Reported operators
Threat actors
1 named in public reportingExploited software
Vulnerabilities linked to Atlantida
2 CVEsMITRE ATT&CK