Formbook - Daily Threat Report

Sunday, August 30, 2026

By Yazoul AI · automated

Daily Summary

Formbook activity on 2026-08-30 shows 61 new samples against a 7-day average of 65, a 7% dip that signals a stable, expected level of operation. No significant surge or drop was observed, and the distribution of file types remained consistent with recent patterns, though the dominance of JavaScript droppers warrants continued attention.

New Samples Detected

JavaScript (.js) files account for 31 of the 61 samples today (51%), outpacing .exe binaries at 20 (33%). This ratio aligns with Formbook’s ongoing shift toward script-based initial payloads, likely to bypass email gateway scanning. The remaining 10 samples split across .ps1 (3), .vbe (3), .vbs (3), and a single .rar archive. The .rar outlier is notable, as it suggests a low-volume but persistent effort to deliver Formbook via password-protected archives, a tactic typically reserved for more targeted operations. No new naming conventions or packaging patterns emerged today.

IOC Highlights

All 61 samples yielded fresh IOCs, bringing today’s total to 61 new indicators. While C2 infrastructure remained static, the file hashes alone provide actionable intel. Analysts should prioritize the 31 .js indicators, as these files often contain embedded URLs or encoded strings that resolve to staging domains. Pulling those strings from the JavaScript files will likely surface secondary infrastructure not yet logged in passive DNS. The single .rar sample’s hash is worth isolating and correlating against email attachment headers if any sandbox detonation triggered a network callback.

Security Analysis

The stable volume masks a subtle signal: Formbook operators are doubling down on JavaScript droppers while keeping C2 infrastructure untouched for at least 48 hours. This combination suggests the current campaign is in a harvesting phase, not an expansion phase. The absence of new C2 domains means defenders should re-focus on the dropper stage rather than hunting for new beacon endpoints. A practical defensive measure: enable script-blocking policies on Windows endpoints for .js files originating from email or browser downloads, and ensure AMSI is enforced on PowerShell to catch the 3 .ps1 samples. Given the .rar outlier, email gateways should also flag archive attachments with no prior sender history, even if password-protected, since that vector often bypasses standard content filtering.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More Formbook Reports

Recent Malware Reports