logo

Infostealer Malware FormBook Spread via Phishing Campaign – Part I

ID: 61610583-cd06-56c0-99ef-62b62936ce85

STIX ID: report--61610583-cd06-56c0-99ef-62b62936ce85

Feed Name: Fortinet Blog

Threat Score
75/100

Date Published: 2025-04-22

Date Updated: 2026-04-27

...
...

Fortinet FortiGuard Labs analyzed a phishing campaign that delivered a malicious Word document exploiting CVE-2017-11882 to execute a 64-bit DLL (disguised as AdobeID.pdf) which establishes persistence, downloads an encrypted FormBook payload disguised as a PNG, decrypts it in memory, and deploys it via fileless process hollowing into ImagingDevices.exe; the report includes detailed TTPs and IOCs (download URL and SHA-256 hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.