FormBook is a Windows information-stealing malware family first discovered in 2016. It steals browser-cached credentials, records keystrokes, captures screenshots, and harvests clipboard contents. Collected information is exfiltrated to attacker-controlled command-and-control infrastructure. FormBook can also download and execute additional malicious files. Samples use decoy domains alongside operational command-and-control destinations to complicate infrastructure analysis.
Distribution commonly involves phishing and malspam with purchase-order, invoice, payment, procurement, and shipping lures. Delivery mechanisms include malicious Word, Excel, and RTF documents exploiting CVE-2017-0199 or CVE-2017-11882, as well as executable payloads inside compressed archives. GuLoader and NeedleDropper have been used to deliver FormBook. Horus Protector-based deployments use obfuscated scripts, encoded payload storage in the Windows registry, memory-resident loading, and process hollowing to execute FormBook inside legitimate processes. Some of these delivery chains establish scheduled-task persistence and check for security software or debugging activity.
FormBook is used by multiple threat actors, including TA558 and Sweed, rather than being exclusive to one operator. Campaigns have targeted organizations worldwide, including maritime and logistics businesses, industrial and manufacturing organizations, government entities, universities, and financial personnel. Its credential-stealing capabilities make it useful in campaigns associated with business email compromise, although subsequent payment fraud is not established for every observed infection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Their C&C infrastructure, with IP addresses 5.181.80.120 and 5.181.80.115, had previously disseminated multiple bait documents carrying the CVE-2017-11882 vulnerability. ... As a result, they downloaded and executed various commercial espionage-oriented banking trojans, including Lokibot and Formbook.
When clicked on, the Word document exploits CVE-2017-0199 automatically downloading an RTF document using the URL stored in the ‘word/_rels/settings.xml.rels’ file.
Elastic tracked a FORMBOOK information-stealing campaign leveraging the MSHTML remote code exploit (CVE-2021-40444). Attackers used malicious Microsoft Office documents with externally linked MHTML OLE objects and ActiveX controls to achieve remote code execution and load subsequent payloads. | The Elastic Intelligence & Analytics team is tracking a new FORMBOOK information-stealing campaign leveraging the MSHTML remote code exploit (CVE-2021-40444).
It was also observed in 2018, distributed via emails with DOCX files that contained a URL. This URL downloaded an RTF file that exploits CVE-2017-8570 and drops an executable. This executable downloads the Formbook sample. | Formbook is an infostealer that has been advertised for sale in public hacking forums since February 2016... It is more advanced than a keylogger as it can retrieve authorization and login credentials from a web data form before the information reaches a secure server, bypassing HTTPS encryption.
The analytic detects a Microsoft Office product spawning the Windows msdt.exe process... Annotations ... CVE CVE-2022-30190 ... Associated Analytic Story ... Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190 ... https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability | References https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/trojanized-onenote-document-leads-to-formbook-malware/
BITTER has exploited Microsoft Office vulnerabilities... CVE-2018-0798...
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“A Word document was attached to the email with a CVE 2017-11882 exploit that called out to kungfrdyeducationalinvestment8agender[.]duckdns[.]org to download another document, and an executable file assessed to be Formbook malware.”
The Guloader file accesses a Google Drive to get the malware payload, FormBook.
常用的攻击工具包括疑似自主开发的office文档公式编辑器漏洞利用工具、恶意office宏制作工具、AgentTesla木马、Formbook木马、Lokibot木马。
These campaigns, detailed in our previous report, distributed payloads that included AgentTesla, Formbook, Lokibot, Netwire and Betabot.
...the delivered payload is in favor of publicly sold malware such as NanoCore, Formbook, etc...
30 distinct techniques documented for this family, organized by ATT&CK tactic.
1,559 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
They complement earlier reporting on AI assisted XLoader malware analysis, where researchers combined model output with runtime checks.
They complement earlier reporting on AI assisted XLoader malware analysis, where researchers combined model output with runtime checks.
FormBook is used to harvest credentials and clipboard data from recipients of malicious email attachments. In this campaign, it contacted operator-controlled C2 infrastructure, while carrying reshuffled decoy-domain lists intended to hinder infrastructure analysis. The stolen information supports business email compromise and payment-redirection fraud.
An infostealer delivered via emails masquerading as Turkish bank-account transaction statements.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.