logo

FORMBOOK Adopts CAB-less Approach

ID: 1f95badc-f8bd-5297-b39b-d5e1e3b7edb9

STIX ID: report--1f95badc-f8bd-5297-b39b-d5e1e3b7edb9

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2022-06-07

Date Updated: 2026-04-27

...
...

Elastic Intelligence describes a multi-phase FORMBOOK info-stealing campaign that used the MSHTML CVE-2021-40444 exploit in testing and production before reverting to traditional phishing attachments; the report includes detailed technical analysis of the malicious Office/ActiveX/PowerShell attack chain, VMProtected payloads, hosted infrastructure (notably 104.244.78.177), extensive indicators (file hashes, domains, IPs), MITRE mappings, detection queries and a YARA rule, and defensive recommendations for patching, monitoring and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.