Formbook - Daily Threat Report

Sunday, August 16, 2026

By Yazoul AI · automated

Daily Summary

Formbook activity surged to 100 new samples on 2026-08-16, a 79% increase over the 7-day average of 56. This marks the highest single-day volume in at least two weeks and signals an active campaign push, likely tied to a fresh phishing wave rather than organic malware drift.

New Samples Detected

The file-type distribution shifted notably today. JavaScript files (48) edged out executables (43) for the first time this week, reversing the usual .exe dominance. This split suggests a bifurcated delivery model: JS files for email attachment lures (likely leveraging HTA or WSH execution chains), and .exe payloads for direct download or archive-based campaigns. The remainder includes 5 .vbs, 2 numeric-extension files (.15420, .21930) consistent with random extension renaming seen in recent Formbook builds, and 1 .rtf likely exploiting CVE-2017-11882 or similar OLE injection to fetch the payload. The low-volume outlier extensions are consistent with small-scale testing, not a strategic shift.

7-Day Trend

Today’s 100 samples deviate 78.6% above the 7-day average, far exceeding the 25% threshold. The prior two days trended near the average (54 and 61), making this spike abrupt rather than a gradual climb. This pattern aligns with a coordinated malspam blast deployed during business hours in European time zones, rather than organic botnet churn. SOC teams should expect elevated volume to persist for 48-72 hours as follow-up waves land.

IOC Highlights

All 100 new samples are registered as fresh IOCs, but the marked absence of new C2 domains or IPs is the standout detail. The malware is connecting to pre-existing infrastructure, meaning defenders with up-to-date C2 blocklists already have partial coverage. The 100 IOCs are mostly file hashes and URLs tied to the initial drop stages. Prioritize the 48 JS hashes for immediate blocking, as they are the primary entry vector today.

Security Analysis

The surge in JS-first delivery with zero new C2 infrastructure suggests the operators are reusing a proven campaign template rather than innovating. This is consistent with Formbook’s established playbook of mass low-quality phishing emails, but the 79% volume spike indicates a new customer or reseller pushing the builder. The numeric-extension files are a tell: they often bypass naive extension-based allowlists in email gateways, yet are trivially caught by content inspection. Recommend hardening email filtering to block JS attachments outright in high-risk departments and force macro-less viewing for .rtf files. Additionally, ensure endpoint detection rules flag any process spawning wscript.exe or cscript.exe from email-downloaded files, as this remains the primary execution chain for Formbook’s JS lures.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More Formbook Reports

Recent Malware Reports