Daily Summary
Formbook activity spiked sharply on 2026-10-04, with 64 new samples collected against a 7-day average of 29. That is a 117% increase over baseline and the highest single-day count in the observed window. The surge is driven primarily by script-based droppers rather than the .exe payloads that have historically dominated Formbook distribution.
New Samples Detected
The file type mix marks a meaningful shift. Script formats account for 39 of 64 samples (roughly 61%), with .js alone contributing 25. Combined with 4 .wsf, 3 .bat, 2 .vbe, 2 .hta, 2 .ps1, and 1 .vbs, the Windows Script Host and browser-based execution chain is clearly the delivery mechanism of choice today. Executables sit at only 10 samples, and .com and .bin contribute 7 each. The .com and .bin presence is worth tracking: both are frequently used as intermediate loader stages that fetch the final Formbook payload, and their appearance alongside a script-heavy dropper set suggests a multi-stage pipeline rather than direct executable delivery.
Distribution Methods
The dominance of .js, .wsf, and .hta points to a phishing or web-delivered campaign relying on user execution of script files. .hta and .js are common in email attachment lures and drive-by downloads where the script is opened from a browser or archive. The low executable count suggests actors are favoring formats that bypass simple attachment filtering and static AV signatures, pushing execution to the scripting engine instead.
C2 Infrastructure
One new C2 server was identified, paired with 65 new IOCs. A single new C2 against 64 samples indicates heavy reuse of existing infrastructure, which is consistent with Formbook’s known operating model of renting or reusing established panels rather than standing up fresh infrastructure per campaign. The high IOC count relative to a single new server reflects the script payloads carrying distinct URLs, mutexes, or hashes across samples.
7-Day Trend
At 64 samples versus a 29 average, today exceeds the threshold for a notable deviation. This is a 2.2x jump and breaks from the prior week’s range. Whether this is a sustained campaign ramp or a single-day burst should be confirmed over the next 48 hours; a single day does not establish a trend, but the breadth of script formats suggests coordinated distribution rather than coincidental collection.
Security Analysis
The script-heavy profile here diverges from the classic Formbook pattern, where .exe and weaponized Office documents typically lead. This mirrors a broader industry shift toward living-off-the-land script execution, and the simultaneous appearance of .com and .bin intermediates suggests the .js and .wsf files are first-stage loaders that pull a secondary payload. Defenders who tune detections around executable Formbook samples risk missing this chain entirely. Recommended action: enable script block logging and Windows Script Host parent-child process monitoring, and alert on wscript.exe, cscript.exe, or mshta.exe spawning network connections or child processes. Treat any .js, .wsf, or .hta attachment opened from email or download as a high-priority investigation trigger for the next several days.