Wordfence cybersecurity researchers: The versions involved are up to, and including, 0.3.11. The issue has been completely fixed in 0.3.12.
Technical analysis by the Malware Hunter JAMESWT
New Formbook campaign via “partial payment”. The rar attachment contains a COM executable, the malware itself. Objective: to steal sensitive data from victims
New Formbook campaign via “partial payment”.
The email contains a compressed attachment in rar format with a COM executable file inside: the malware itself. This, if opened, starts the chain of infection. The goal of cybercrime is to steal sensitive data from victims. Formbook, in fact, through the keylogger function, is able to acquire everything the user types. It can also steal email and browser credentials, as well as take screenshots. Finally, it has the ability to remotely issue commands on the infected PC, such as downloading additional payloads or updating those present.