Formbook Malware Targets Global Organizations Through Phishing Campaigns
Organizations across several countries, including South American nations, Bosnia, Croatia, Greece, Slovenia, and Spain, have been targeted by the Formbook information-stealing malware through sophisticated phishing campaigns. According to Infosecurity Magazine, these attacks involve two distinct methods. The first campaign uses malicious emails with RAR attachments containing DLLs and a Windows executable file, employing DLL side-loading to execute Formbook undetected. The second campaign utilizes phishing emails with JavaScript and PDF files that conceal the malware payload. When the JavaScript is executed, it injects image files that deploy PowerShell commands, leading to the execution of a Windows executable that launches a Formbook-injecting malware loader. This loader has been previously used to deliver other malware such as AsyncRAT, Remcos, XWorm, and SmokeLoader.