Formbook Phishing Campaign with old Payloads
ID: ea7d8a89-0661-5095-8532-a0b761e4987f
STIX ID: report--ea7d8a89-0661-5095-8532-a0b761e4987f
Feed Name: Seqrite Blog
Seqrite Lab analyzed a spear-phishing campaign delivering FormBook infostealer via a multi-stage loader: a .NET dropper (PurchaseOrder.exe) unpacks and decrypts Arthur.dll, which extracts and loads Montero.dll from steganographic image data; Montero.dll decrypts a MASM-compiled final payload and deploys it via in-memory execution or process hollowing. The report details sandbox-evasion and persistence behaviors (mutex, sleep delays, scheduled tasks, exclusion creation), provides IOCs (hashes, YARA rule) and maps observed behavior to MITRE ATT&CK techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
