---
title: "Banshee Stealer Unveiled, Corrupted Word Phishing, AI Voice Scams, Cybersecurity News [December 02, 2024] | DuoCircle"
description: "Banshee Stealer Unveiled, Corrupted Word Phishing, AI Voice Scams, Cybersecurity News [December 02."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-50-of-2024/"
---

Quick Answer

Cybersecurity news for the week of December 2, 2024\. The macOS infostealer Banshee Stealer ($3,000/month subscription) shut down operations after its source code was leaked online; the malware targeted browser data, keychain passwords, and crypto wallets including Electrum, Wasabi, Atomic, Exodus, and Coinomi across Chrome, Opera, Safari, and Firefox. Coverage also included a phishing campaign delivering corrupted Word documents to evade detection, AI-generated voice scams, and other social engineering trends, plus user awareness and patching guidance.

Banshee Stealer Unveiled, Corrupted Word Phishing, AI Voice Scams, Cybersecurity News \[December 02, 2024\]

Your browser does not support the audio element.

[ Download episode](https://media.mailhop.org/duocircle/images/2024/12/Banshee-Stealer-Unveiled-Corrupted-Word-Phishing-AI-Voice-Scams-–-Cybersecurity-News-December-02-2024.mp3) 

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-50-of-2024%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Banshee%20Stealer%20Unveiled%2C%20Corrupted%20Word%20Phishing%2C%20AI%20Voice%20Scams%2C%20Cybersecurity%20News%20%5BDecember%2002%2C%202024%5D&url=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-50-of-2024%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-50-of-2024%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-50-of-2024%2F&title=Banshee%20Stealer%20Unveiled%2C%20Corrupted%20Word%20Phishing%2C%20AI%20Voice%20Scams%2C%20Cybersecurity%20News%20%5BDecember%2002%2C%202024%5D "Share on Reddit") [ ](mailto:?subject=Banshee%20Stealer%20Unveiled%2C%20Corrupted%20Word%20Phishing%2C%20AI%20Voice%20Scams%2C%20Cybersecurity%20News%20%5BDecember%2002%2C%202024%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-50-of-2024%2F "Share via Email") 

![cybersecurity news](https://media.mailhop.org/duocircle/images/2024/12/email-smtp-service-1.jpg) 

The cybercriminal breed is expanding at a tremendous rate, necessitating **urgent remedial measures** from the relevant involved parties. _Cybercriminals are also upscaling their operations and taking sufficient precautionary measures to prevent getting caught_. Unfortunately, the public, who end up as unsuspecting victims, needs to pull up their socks and act responsibly to avoid becoming victims of cybersecurity fraud. This week’s [cybersecurity](/) news focuses on these aspects and aims to educate people to become more aware of the [ever-evolving cyber threat landscape](https://cybermagazine.com/articles/the-rapidly-evolving-threat-landscape-of-2024).

## Operations Behind Banshee Stealer Shut Down

How would cybercriminals feel if they got a taste of their own medicine? The malicious actors behind the Banshee Stealer malware experienced this **firsthand last week** when they discovered that the Banshee Stealer [source code](https://github.com/vxunderground/MalwareSourceCode/blob/main/MacOS/MacOS.Stealer.Banshee.7z) had been [leaked online](https://x.com/vxunderground/status/1861148329884753939). So, what did they do? They shut down their operations immediately.

What is Banshee Stealer, and why was there an urgency to shut down operations? Banshee Stealer is malware developed by state [threat actors](/email-security/what-threat-actor-can-do-with-your-emails-without-password/) to collect data from [infected macOS devices](https://thehackernews.com/2023/04/lockbit-ransomware-now-targeting-apple.html). _The target data includes user passwords, system info, web browser data, passwords from keychains, and cryptocurrency wallets, such as Electrum, Wasabi Wallet, Atomic, Exodus, and Coinomi_. It can steal data from almost all **web browsers**, including Chrome, Opera, Safari, and Firefox. 

[Banshee Stealer](https://www.securityweek.com/new-banshee-stealer-macos-malware-priced-at-3000-per-month/) was available on [cybercrime forums](https://cyberscoop.com/breachforums-a-key-english-language-cybercrime-forum-seized-by-the-fbi/) for a monthly subscription of $3,000\. Though it is malware, it lacks sophisticated obfuscation. _However, its operations were shut down last week following a source code leak online_. As of now, no one knows who leaked the code and why. Cybercriminals shut down operations because the source code leak made it easier for **cybersecurity researchers** to analyze and develop countermeasures against this threat.

## An Innovative Phishing Campaign Using Corrupted MS Word Documents

Cybercriminals are becoming more innovative by the day. A malware-hunting firm, [Any.Run](https://x.com/anyrun%5Fapp/status/1861024182210900357) has discovered a unique [phishing campaign](https://www.cbsnews.com/news/black-friday-phishing-scam-how-to-spot/) in which malicious actors use **MS Word’s file recovery feature** to sneak corrupted MS Word files into emails to unsuspecting recipients. 

Generally, these emails originate from companies’ HR and payroll departments, making them look genuine. They contain **MS Word documents** that include the base64-encoded string “IyNURVhUTlVNUkFORE9NNDUjIw.” When you try to download and open the attachments, the files do not open. The message that the file is corrupted flashes and asks the user whether they wish to recover it.

_When the user confirms the action, it displays a document, asking them to scan a QR code to retrieve it_. Scanning the code leads the user to a phishing website resembling the **MS login page**. These file attachments bypass [email security](/content/email-security-services) protocols because most antivirus solutions fail to apply proper procedures for such file types. They do not contain any [malicious code](https://www.wired.com/story/qr-codes-phishing-attack/) but display a QR code. As a result, the target ends up compromising their Microsoft user credentials. The solution is to exercise caution when receiving such attachments from unknown senders. You can delete the file or confirm with your network admin before opening it. Utilizing the [QR Code Generator](http://www.the-qrcode-generator.com/) securely can help businesses [create and manage QR codes](https://replug.io/qr-code-generator) while ensuring they are free from malicious intent.

[![compromising personal data](https://media.mailhop.org/duocircle/images/2024/12/hosted-email-server-4587-1.jpg)](https://media.mailhop.org/duocircle/images/2024/12/hosted-email-server-4587-1.jpg)

## AI-generated Voices In Fake Betting Apps Stealing Sensitive Information

AI is proving to be an excellent servant but a terrible master. While AI is handy in almost every aspect of life, threat actors misuse AI capabilities to steal sensitive information. Reports have come in that cybercriminals are using [AI-generated voices in fake betting apps](https://www.group-ib.com/blog/shady-bets/) to lure unsuspecting victims to share **confidential info**. What makes it more dangerous is that scammers use AI-generated voices in different languages to entice people across the globe. 

More than 1377 malicious websites and over 500 [fake ads](https://www.darkreading.com/threat-intelligence/online-ad-fraud-exposed-advertisers-losing-6-3-billion-to-10-billion-per-year) have been identified to target users globally. Numerous victims of these scams have become victims, with some losing over $10,000\. Fake ads prey on human greed and entice users by **promising unrealistic rewards**. Ultimately, it leads to [compromising personal data](https://securityintelligence.com/news/national-public-data-breach-publishes-private-data-billions-us-citizens/) and financial losses.

_You can use reliable sources to download apps and mitigate this risk. People should be aware that anything that promises to be too good to be true is not necessarily genuine_. Overcoming greed and resisting the lure to get quick money is challenging, but that is one way of **preventing becoming a victim** of such [fake betting apps](https://hackread.com/fake-betting-apps-ai-generated-voices-steal-data/). 

## INTERPOL Makes Record With Over 5500 Arrests and $400M Recovery.

INTERPOL’s [five-month operation](https://www.interpol.int/en/News-and-Events/News/2024/INTERPOL-financial-crime-operation-makes-record-5-500-arrests-seizures-worth-over-USD-400-million), HAECHI V, has yielded fruitful results with the arrest of 5500+ cybercriminals spread over **40 countries globally**. This operation targeted seven different types of cyber-enabled frauds, including [e-commerce fraud](https://www.infosecurity-magazine.com/news/ecommerce-fraud-campaign-600-fake/), [voice phishing](https://www.cpomagazine.com/cyber-security/lastpass-reports-voice-phishing-attempt-on-employee-using-audio-deepfake-of-company-ceo/), investment fraud, BEC, online sextortion, [romance scams](https://www.foxnews.com/us/romance-scams-rise-americans-look-dating-apps-love-5-tips-protect-yourself), and [illegal online gambling](https://www.yogonet.com/international/news/2024/06/04/72484-illegal-online-gambling-reaches-95-bn-in-new-york-new-jersey-and-minnesota-according-to-cfg-report). This operation has resulted in the seizure of over $400M in government-backed securities and virtual assets.

In addition, INTERPOL has tightened its screws on emerging fraud techniques such as [cryptocurrency fraud](https://apnews.com/article/cryptocurrency-fraud-fbi-report-29b412330ccebce946dec895f5060fd7) practices involving **USDT stablecoin**. It has issued a Purple notice alerting member countries of the USDT Token Approval Scam that allows cybercriminals to access and control the victim’s cryptocurrency wallets. 

[![Protect Yourself from Romance Scams](https://media.mailhop.org/duocircle/images/2024/12/what-is-dkim-selector.jpg)](https://media.mailhop.org/duocircle/images/2024/12/what-is-dkim-selector.jpg)

## Beware Of Online Scams, Follow Cybersecurity Best Practices

Black Friday has already arrived, and online shopping has heated up globally, especially with **Christmas and the New Year** approaching shortly. These [cybersecurity awareness tips](https://www.cisa.gov/shop-safely-holiday-season) should prevent you from being scammed online. 

1. _Update your software to protect your data from known threats_.
2. Use strong passwords and change them frequently. A reliable password manager can help store them. Turning on MFA wherever available provides extra protection.
3. Beware of phishing messages; never click on unknown links or download unsolicited attachments.
4. Be careful when you receive requests to share online information. Report the scam to the **law-enforcement authorities** and delete the message completely.
5. Check for https on the browser search bar and ensure the padlock icon is locked. It ensures encryption.
6. Choose reputable vendors and pay using your credit cards instead of debit cards. Credit cards offer **higher levels of protection**.
7. Check your accounts regularly for [suspicious activity](https://www.bleepingcomputer.com/news/security/microsoft-authenticator-now-blocks-suspicious-mfa-alerts-by-default/).

As a result, you safeguard your credentials and avoid becoming a victim of e-commerce fraud and losing your hard-earned money.

## Topics

cyber securityemail securityNewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

## Related Articles

[  News 4m  Cambodia Targets Cybercriminals, Traditional Security Insufficient, AI Against Phishing, Cybersecurity News \[March 09, 2026\]  Mar 16, 2026 ](/blog/announcements/cyber-security-news-update-week-11-of-2026/)[  News 6m  Lazarus Infects NPM, MassJacker Steals Crypto, CISA Alerts Ivanti, Cybersecurity News \[March 10, 2025\]  Mar 17, 2025 ](/blog/announcements/cyber-security-news-update-week-12-of-2025/)[  News 6m  RedCurl Ransomware Targets, CS2 Steam Phishing, Fake Converter Cyberattacks , Cybersecurity News \[March 24, 2025\]  Apr 1, 2025 ](/blog/announcements/cyber-security-news-update-week-14-of-2025/)[  News 5m  Essential Check Secures, Prevention Beats Recovery, Treasury Cyber Breach- Cybersecurity News \[December 30, 2024\]  Jan 6, 2025 ](/blog/announcements/cyber-security-news-update-week-2-of-2025/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Banshee Stealer Unveiled, Corrupted Word Phishing, AI Voice Scams, Cybersecurity News [December 02, 2024]","description":"Banshee Stealer Unveiled, Corrupted Word Phishing, AI Voice Scams, Cybersecurity News [December 02.","url":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-50-of-2024/","datePublished":"2024-12-09T17:33:05.000Z","dateModified":"2025-06-17T14:11:19.000Z","dateCreated":"2024-12-09T17:33:05.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-50-of-2024/"},"articleSection":"announcements","keywords":"cyber security, email security, News, Security, Updates","wordCount":1011,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/12/email-smtp-service-1.jpg","caption":"cybersecurity news","width":900,"height":506},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Banshee Stealer Unveiled, Corrupted Word Phishing, AI Voice Scams, Cybersecurity News [December 02, 2024]","item":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-50-of-2024/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Banshee Stealer Unveiled, Corrupted Word Phishing, AI Voice Scams, Cybersecurity News [December 02, 2024]","item":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-50-of-2024/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Banshee Stealer Unveiled, Corrupted Word Phishing, AI Voice Scams, Cybersecurity News [December 02, 2024]","description":"Banshee Stealer Unveiled, Corrupted Word Phishing, AI Voice Scams, Cybersecurity News [December 02.","url":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-50-of-2024/","datePublished":"2024-12-09T17:33:05.000Z","dateModified":"2025-06-17T14:11:19.000Z","dateCreated":"2024-12-09T17:33:05.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-50-of-2024/"},"articleSection":"announcements","keywords":"cyber security, email security, News, Security, Updates","wordCount":1011,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/12/email-smtp-service-1.jpg","caption":"cybersecurity news","width":900,"height":506},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
