Multiple investigations detailed FormBook being delivered through phishing lures that abused disguised attachments, malicious .pps files, RAR archives with fake PDF .lnk files, and PowerShell droppers masquerading as images such as ad.jpg. Across the campaigns, the initial stages launched heavily obfuscated PowerShell, HTA, VBScript, or .NET loaders that used Base64, AES, GZip, XOR decoding, AMSI bypasses, and staged payload extraction to retrieve additional components from attacker-controlled domains. Analysts observed decoy documents, shortened URLs, and NSIS-based installers used to conceal the infection chain before the malware was injected into legitimate Windows processes such as AddInProcess32.exe, ImagingDevices.exe, and other suspended binaries.
The final FormBook payload consistently used process hollowing, shared-memory injection, duplicated ntdll.dll, API hashing, anti-VM, anti-sandbox, anti-debugging, and even Heaven’s Gate transitions to evade analysis and endpoint defenses. Once running, the infostealer harvested system details, browser and email credentials, cookies, autofill data, clipboard contents, proxy settings, and data from messaging and FTP clients, then exfiltrated the information over obfuscated, encrypted, and Base64-encoded HTTP traffic to rotating command-and-control infrastructure. Researchers also documented operator commands that let attackers download and execute files, run commands, wipe browser data, remove the malware, and reboot or shut down infected systems.

Pull IOCs and campaign context straight into your stack.
9 events from the most recent confirmed update back to the earliest known activity.
FortiGuard Labs reported on a FormBook variant running inside ImagingDevices.exe that used duplicated ntdll.dll, Heaven’s Gate transitions, anti-VM and anti-debugging checks, and process hollowing into SysWOW64 binaries such as PATHPING.EXE. The report also documented a separate injected socket process for C2 communications, theft of browser and Outlook data, and 64 obfuscated C2 domains.
FortiGuard Labs reported a phishing campaign using a fake sales-order Word document that loaded an external RTF via altChunk and exploited CVE-2017-11882 in Microsoft Equation Editor to run a disguised DLL named AdobeID.pdf through rundll32.exe. The DLL established persistence, downloaded and decrypted an in-memory payload masquerading as a PNG file, and hollowed ImagingDevices.exe to execute a fileless FormBook variant; Fortinet also published related IOCs.
A researcher described a phishing campaign in which a RAR archive contained a disguised PDF-themed LNK file that launched PowerShell, retrieved an HTA from thanhancompany[.]com, and executed a multi-stage PowerShell chain. The infection downloaded a decoy PDF and a .NET payload named 883.exe, which unpacked the final FormBook malware.
A malware analysis write-up examined a FormBook sample delivered as a 32-bit NSIS installer that extracted a DLL and staged files, decoded hicclc.io with a hardcoded XOR key, and used shellcode plus process hollowing to run the final payload. The analysis highlighted fresh NTDLL mapping for EDR evasion and credential theft targeting browsers, cookies, clipboard data, and stored credentials.
Quick Heal published analysis of a FormBook variant that used steganography and multi-stage in-memory loading to steal data. The report characterized it as a returning/new variant with updated delivery and execution tradecraft.
In part II of its analysis, FortiGuard Labs described how the FormBook payload injected into AddInProcess32.exe duplicated ntdll.dll, performed anti-analysis checks, injected into Explorer.exe, and then into a suspended Windows process such as ipconfig.exe. The report also documented process targeting for credential theft and command-and-control support.
FortiGuard Labs reported a phishing campaign using a malicious PowerPoint .pps attachment masquerading as a purchase-order reply to infect Windows users with a new FormBook variant. The attachment triggered VBA macros that launched PowerShell, downloaded additional code from a shortened URL resolving to kiibra[.]com, reconstructed item3.jpg, and ultimately injected FormBook into AddInProcess32.exe.
SANS ISC analyzed a malicious file named ad.jpg that was actually a Base64-encoded PowerShell script using an AMSI bypass, in-memory DLL loading, and anti-VM checks before executing a final FormBook payload. The analysis identified multiple contacted domains and noted the sample and extracted payloads were not present on VirusTotal at the time of analysis.
Malware-Traffic-Analysis.net documented a FormBook infection run observed on 2023-06-05 involving a RAR archive named "Release_pending_bookings_now.rar" that contained a Windows executable disguised with an Adobe PDF-style icon. The malware established persistence via the HKCU Run key, staged screenshots and credential-recovery files under the user's Roaming profile, and sent stolen data via HTTP POST requests to multiple domains, with qfs-capital[.]com appearing to accept the exfiltrated data.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 247 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
9 references tracked. Mallory keeps watching after this page renders.
fortinet.com
Open sourcefortinet.com
Open sourcekienmanowar.wordpress.com
Open sourcegithub.com
Open sourcemalware-traffic-analysis.net
Open sourceblogs.quickheal.com
Open sourcefortinet.com
Open sourcefortinet.com
Open sourceisc.sans.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.