FORMBOOK Adopts CAB-less Approach
ID: 1f95badc-f8bd-5297-b39b-d5e1e3b7edb9
STIX ID: report--1f95badc-f8bd-5297-b39b-d5e1e3b7edb9
Feed Name: Elastic Security Labs
Elastic Intelligence describes a multi-phase FORMBOOK info-stealing campaign that used the MSHTML CVE-2021-40444 exploit in testing and production before reverting to traditional phishing attachments; the report includes detailed technical analysis of the malicious Office/ActiveX/PowerShell attack chain, VMProtected payloads, hosted infrastructure (notably 104.244.78.177), extensive indicators (file hashes, domains, IPs), MITRE mappings, detection queries and a YARA rule, and defensive recommendations for patching, monitoring and hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
