Formbook - Daily Threat Report

Sunday, August 2, 2026

By Yazoul AI · automated

Daily Summary

Formbook activity on 2026-08-02 totaled 33 new samples, a 46% decline from the 7-day average of 61. This marks the third consecutive day of below-average volume, continuing a steady downward trend after a notable spike late last week.

New Samples Detected

The file type distribution shifted notably today. JavaScript-based payloads (.js) dominated with 19 samples (58%), followed by Windows executables (.exe) at 12 samples (36%). The remaining samples included one RTF document and one file with an unusual .81626146 extension, likely an artifact of an automated packing routine rather than a deliberate evasion tactic.

The .js-to-.exe ratio of roughly 1.6:1 is significantly higher than the 7-day baseline of approximately 1:1. This tilt toward script-based delivery suggests threat actors are favoring lightweight, easily obfuscated JavaScript loaders over compiled binaries, which aligns with prior Formbook campaigns that use PowerShell or WScript to stage the final payload in memory.

7-Day Trend

Today’s 33 samples represent a 46% drop from the 7-day average of 61, a deviation well beyond the 25% threshold that warrants attention. Over the past week, volume peaked at 87 samples on July 28, then progressively declined to today’s low. This pattern mirrors the post-campaign lull observed in previous Formbook waves, where a burst of activity tied to a mass phishing run is followed by several days of reduced output as infrastructure is rotated or campaigns conclude.

IOC Highlights

All 33 samples yielded new IOCs, though no new C2 domains or IPs were identified. The bulk of these IOCs are file hashes (SHA-256) tied to the observed payloads. Analysts should ingest these hashes into their blocklists proactively, as Formbook samples frequently resurface in later campaigns with only minor packing changes, leaving the underlying hash still valid for detection.

Security Analysis

The absence of new C2 infrastructure during a period of declining sample volume is notable. Typically, a campaign wind-down coincides with fresh C2 domains or IPs being provisioned for the next wave. Here, the static C2 picture suggests the operators are either maintaining the same infrastructure for an upcoming push or are in a holding pattern while they reassess their delivery mechanisms. The elevated .js ratio may hint at a pivot toward email-based campaigns that bypass traditional executable attachment filters.

Defensive teams should treat this lull as preparation time, not a signal to relax. Prioritize updating email gateway rules to flag JavaScript attachments with macro-like behavior or suspicious script obfuscation, and ensure endpoint detection rules are tuned to catch WScript and PowerShell execution chains that Formbook’s JS loaders commonly abuse.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More Formbook Reports

Recent Malware Reports