Daily Summary
Formbook activity rose 16% on 2026-07-05 with 43 new samples, surpassing the 7-day average of 37. The 6-sample uplift was driven by an unusual spike in JavaScript and batch file variants, signaling a shift in initial delivery tactics.
New Samples Detected
The sample type breakdown showed a marked deviation from recent norms. JavaScript files accounted for 12 of the 43 samples (28%), nearly double their typical share. Batch files also surged to 5 samples, a four-fold increase over the quiet .exe-dominant patterns observed in late June. The sole .com and .vbs samples are consistent with Formbook’s historical use of legacy script engines for initial execution, but their reappearance alongside the JS and bat surge suggests a coordinated campaign refreshing payload delivery wrappers.
C2 Infrastructure
37 new C2 servers emerged, a 26% increase over the 7-day average of 29. Analysis of 80 new IOCs disclosed no concentration in any single geographic region, but query patterns on the new servers show a 40% increase in HTTP POST beacon intervals (now averaging 90 seconds vs 60 seconds) across 15 domains. This throttling may indicate efforts to evade behavioral detection thresholds common in cloud-based SOC tools.
Security Analysis
The rise in JavaScript and batch file samples, combined with extended C2 beacon intervals, mirrors techniques used in the ‘RapidWraps’ campaign from Q2 2025, where Formbook was packaged in VBS-JS hybrids to bypass email gateway scanners. Defensive teams should deploy enhanced telemetry on process creation events for wscript.exe and cmd.exe launching from user-writable directories like %TEMP% and %APPDATA%, as these paths were observed as execution origins in 9 of today’s 12 JS samples.