skip to Main Content

Cybercrime, fake payment notice hides Formbook

Malware Hunter JAMESWT Technical Analysis

A false payment notice hides Formbook. The email ace attachment contains an exe file: the malware itself

A false payment notification via email with the subject “Payment Advice – Advice Ref: [] / ACH credits / Customer Ref: []” is the bait of a new Formbook campaign.

The ace attachment contains an exe file: the malware itself. Formbook, through the keylogger function, is able to acquire everything the user types. It can also steal email and browser credentials, as well as take screenshots. Finally, it has the ability to remotely issue commands on the infected PC, such as downloading additional payloads or updating those present.

Malware C2

Back To Top