Formbook Malware Campaign Uses Multiple Obfuscation Techniques to Avoid Detection
ID: 3c37f786-9f23-50ef-8537-fe4107fc8ae6
STIX ID: report--3c37f786-9f23-50ef-8537-fe4107fc8ae6
Feed Name: Infosecurity Magazine (News)
Two phishing campaigns are actively distributing the Formbook infostealer to Windows systems across multiple countries (Greece, Spain, Slovenia, Bosnia, Croatia and parts of South America). One campaign uses DLL sideloading via RAR attachments containing DLLs and an EXE, while the other uses obfuscated JavaScript and PDFs that drop images which in turn execute obfuscated PowerShell to run a loader and deploy Formbook; WatchGuard highlights the campaigns' evasion of detection and advises monitoring archive-based attachments, anomalous DLL loading, PowerShell execution tied to attachments, and signs of manual DLL mapping or direct syscalls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
