Daily Summary
Formbook sample volume surged to 100 new detections on 2026-07-12, a 155% increase over the 7-day average of 39. This marks the largest single-day spike observed in the current tracking window, driven primarily by a sharp rise in .exe and .js samples.
New Samples Detected
The file type distribution shifted notably today. Executables (.exe) accounted for 65 samples, consistent with Formbook’s historical preference, but the 22 JavaScript (.js) detections represent a significant uptick from the trailing average of 6-8 per day. This suggests an active phishing campaign using script-based initial loaders, likely delivered as email attachments. The presence of 5 .vbs and 5 .hta files further supports a distribution strategy that favors lightweight, script-based droppers designed to bypass network-level file filtering.
C2 Infrastructure
Thirteen new C2 servers were identified today, a considerable expansion given the 7-day average of approximately 4-5 per day. While the geographic distribution of these servers was not reported as a top country, the volume alone indicates possible automated C2 provisioning or a shift to ephemeral hosting providers. Analysts should cross-reference these IPs and domains against known residential proxy and bulletproof hosting ASNs.
7-Day Trend
At 155% above the 7-day average, today’s count represents the most aggressive deviation in recent monitoring. The 14-day trend extrapolation suggests sustained elevation unless deployment infrastructure is disrupted. The rise is concentrated in script-based delivery mechanisms, not a wide diversification of initial access methods.
Security Analysis
The simultaneous spike in both .exe and .js samples, coupled with a dramatic increase in C2 infrastructure, mirrors Formbook’s campaign pattern from Q1 2026 where a single email blast seeded multiple loader types to the same victim population. The 22 .js samples likely share a common obfuscation or downloader template, suggesting a single threat actor is driving this surge rather than multiple independent groups. Defenders should prioritize blocking execution of JavaScript from email attachments and implement AMSI-based scanning for inline VBS and HTA scripts, as these vectors currently have higher bypass potential than traditional .exe execution.