skip to Main Content

Cybercrime, new FormBook global campaign via Modiloader

Technical Analysis of Malware Hunter JAMESWT

New FormBook global campaign via Modiloader. The rar attachment contains an exe file: the loader itself, which contacts a link and downloads the final malware

“RE: URGENT QOUTATION” is the subject of an email that conveys a new global Formbook campaign via Modiloader.

The rar attachment contains an exe file: the loader itself, which contacts a link and downloads the final malware.

Formbook, through the keylogger function, is able to acquire everything the user types. It can also steal email and browser credentials, as well as take screenshots. Finally, it has the ability to remotely issue commands on the infected PC, such as downloading additional payloads or updating those present.

Malware C2

Back To Top