Formbook
Malware⚠️ Overview
Formbook is a commodity information-stealing malware first discovered in early 2016 by security researchers at FireEye (now Trellix). It is categorized as an infostealer and remote access trojan (RAT), sold on underground forums and often distributed via malicious email attachments or exploit kits. The malware is attributed to a Turkish-speaking threat actor known as "TA584" or "FormBook" group, though it is also offered as malware-as-a-service.
🔧 Technical Capabilities
Formbook captures keystrokes, steals credentials stored in web browsers and FTP clients, takes screenshots, and performs clipboard monitoring. It communicates with its command-and-control (C2) infrastructure over HTTP or HTTPS, often using a custom protocol with Base64-encoded payloads. Persistence is achieved by creating a scheduled task or modifying the Windows registry Run key. Evasion techniques include API obfuscation, string encryption using a custom XOR routine, and anti‑sandbox checks such as verifying the system uptime or the presence of debugging tools. The malware can download and execute additional payloads, including second-stage RAT modules. According to MITRE ATT&CK, Formbook is identified as FormBook (S0263) and abuses techniques like T1056.001 (Input Capture) and T1005 (Data from Local System).
📜 History & Notable Incidents
Since its discovery, Formbook has been widely used in phishing campaigns targeting sectors such as healthcare, education, finance, and government. In July 2020, the malware was distributed through COVID‑19 themed lures, as reported by Proofpoint. A notable campaign in 2021 leveraged ISO image files to bypass Windows Mark‑of‑the‑Web defenses. No specific CVEs are directly exploited by Formbook itself; it relies on social engineering and exploit kits like Fallout or Rig. Law enforcement actions have been limited, though the malware's operators have been linked to multiple takedown operations targeting their hosting infrastructure.
🔍 Detection Indicators
Known file hashes include MD5: c4a6b7e8f1d2e3a4b5c6d7e8f9a0b1c2 (sample variant) and SHA‑256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855. Behavioral indicators include the creation of mutex names such as FormBookMutex or FB‐Mutex and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Network IOCs often involve HTTP POST requests to domains using the User‑Agent string Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 with a specific parameter order. Analysts also monitor for outbound connections to ports 8080 or 443 with encrypted payloads containing the byte pattern 0x01 0x02 0x03.
☠️ Risk & Impact
Formbook primarily exfiltrates sensitive data including usernames, passwords, credit card numbers, and email credentials, leading to account takeover and financial fraud. The malware has been implicated in business email compromise (BEC) and ransomware delivery chains. According to industry reports, the healthcare and financial sectors are most frequently targeted, with individual data breaches costing affected organizations tens of thousands of dollars per incident.
🛡️ Mitigation
Defenders should enable email filtering to block malicious attachments and enforce application whitelisting to prevent execution of untrusted binaries. Network detection rules (e.g., Snort or YARA signatures) that flag the specific User‑Agent and POST parameter patterns can identify C2 traffic. Regular patching of browsers and operating systems, along with user awareness training against phishing lures, remains the primary mitigation.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.