CISA warns of Windows flaw used in infostealer malware attacks

Teilen:

​CISA has ordered U.S. federal agencies to secure their systems against a recently patched Windows MSHTML spoofing zero-day bug exploited by the Void Banshee APT hacking group.

The vulnerability (CVE-2024-43461) was disclosed during this month’s Patch Tuesday, and Microsoft initially classified it as not exploited in attacks. However, Microsoft updated the advisory on Friday to confirm that it had been exploited in attacks before being fixed.

Microsoft revealed that attackers exploited CVE-2024-43461 before July 2024 as a part of an exploit chain with CVE-2024-38112, another MSHTML spoofing bug.

“We released a fix for CVE-2024-38112 in our July 2024 security updates which broke this attack chain,” it said. “Customers should both the July 2024 and September 2024 security update to fully protect themselves.”

Peter Girnus, the Trend Micro Zero Day Initiative (ZDI) threat researcher who reported the security flaw, told BleepingComputer that Void Banshee hackers exploited it in zero-day attacks to install information-stealing malware.

The vulnerability enables remote attackers to execute arbitrary code on unpatched Windows systems by tricking the targets into visiting a maliciously crafted webpage or opening a malicious file.

“The specific flaw exists within the way Internet Explorer prompts the user after a file is downloaded,” the ZDI advisory explains. “A crafted file name can cause the true file extension to be hidden, misleading the user into believing that the file type is harmless. An attacker can leverage this vulnerability to execute code in the context of the current user.”

They used CVE-2024-43461 exploits to deliver malicious HTA files camouflaged as PDF documents. To hide the .hta extension, they used 26 encoded braille whitespace characters (%E2%A0%80).

As revealed in July by Check Point Research and Trend Micro, the Atlantida information-stealing malware deployed in these attacks can help steal passwords, authentication cookies, and cryptocurrency wallets from infected devices.

Void Banshee is an APT hacking group first identified by Trend Micro and known for targeting organizations across North America, Europe, and Southeast Asia for financial gain and to steal data.

Federal agencies given three weeks to patch

Today, CISA has added the MSHTML spoofing vulnerability to its Known Exploited Vulnerabilities catalog, tagging it as actively exploited and ordering federal agencies to secure vulnerable systems within three weeks by October 7, as mandated by Binding Operational Directive (BOD) 22-01.

"Diese Art von Schwachstellen sind häufige Angriffsvektoren für böswillige Cyber-Akteure und stellen ein erhebliches Risiko für das Bundesunternehmen dar", so die Cybersicherheitsbehörde.

Although CISA’s KEV catalog primarily focuses on alerting federal agencies about security flaws they should patch as soon as possible, private organizations worldwide are also advised to prioritize mitigating this vulnerability to block ongoing attacks.

Microsoft has patched three other actively exploited zero-days in the September 2024 Patch Tuesday. This includes CVE-2024-38217, a vulnerability exploited in LNK stomping attacks since at least 2018 to bypass the Smart App Control and the Mark of the Web (MotW) security feature.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
11:20 pm, Juni 23, 2025
Wetter-Symbol 16°C
L: 15° | H: 17°
broken clouds
Luftfeuchtigkeit: 59 %
Druck: 1015 mb
Wind: 5 mph WNW
Windböe: 15 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 54%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 10:00 pm
Wetter-Symbol
15° | 17°°C 0 mm 0% 14 mph 76 % 1015 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 28°°C 0.21 mm 21% 10 mph 86 % 1013 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
17° | 24°°C 1 mm 100% 17 mph 94 % 1018 mb 0 mm/h
Fr. Juni 27 10:00 pm
Wetter-Symbol
15° | 27°°C 0 mm 0% 15 mph 71 % 1021 mb 0 mm/h
Sa. Juni 28 10:00 pm
Wetter-Symbol
17° | 29°°C 0.2 mm 20% 12 mph 85 % 1025 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
14° | 16°°C 0 mm 0% 10 mph 61 % 1015 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
13° | 14°°C 0 mm 0% 9 mph 70 % 1014 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 11 mph 76 % 1014 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 12 mph 72 % 1013 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 14 mph 71 % 1013 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 12 mph 57 % 1011 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 12 mph 49 % 1012 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 9 mph 68 % 1013 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,897.64
4.96%
Ethereum(ETH)
€2,093.23
8.46%
Fesseln(USDT)
€0.87
0.03%
XRP(XRP)
€1.86
7.83%
Solana(SOL)
€126.16
10.57%
USDC(USDC)
€0.87
0.02%
Dogecoin(DOGE)
€0.141597
9.37%
Shiba Inu(SHIB)
€0.000010
10.64%
Pepe(PEPE)
€0.000009
12.25%
Nach oben scrollen