logo

Formbook Phishing Campaign with old Payloads

ID: ea7d8a89-0661-5095-8532-a0b761e4987f

STIX ID: report--ea7d8a89-0661-5095-8532-a0b761e4987f

Feed Name: Seqrite Blog

Threat Score
75/100

Date Published: 2025-01-07

Date Updated: 2026-04-30

Author: Rumana Siddiqui

...
...

Seqrite Lab analyzed a spear-phishing campaign delivering FormBook infostealer via a multi-stage loader: a .NET dropper (PurchaseOrder.exe) unpacks and decrypts Arthur.dll, which extracts and loads Montero.dll from steganographic image data; Montero.dll decrypts a MASM-compiled final payload and deploys it via in-memory execution or process hollowing. The report details sandbox-evasion and persistence behaviors (mutex, sleep delays, scheduled tasks, exclusion creation), provides IOCs (hashes, YARA rule) and maps observed behavior to MITRE ATT&CK techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.