FormBook Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
8
occurrences
First Seen
November 3, 2025
Last Seen
July 20, 2026

Related Threat Clusters

  • Formbook Malware Campaign Targets Organizations with Advanced Phishing Techniques

    Two phishing campaigns have been identified targeting organizations in Greece, Spain, Slovenia, Bosnia, Croatia, and several South American countries, aiming to deliver the Formbook infostealer malware. The first…

    2 articles · Updated April 21, 2026
  • Cruciferra Crypter Service Powers Multiple Cybercrime Campaigns

    Proofpoint has identified a sophisticated crypter service named Cruciferra, first sold in autumn 2025, that is utilized by various cybercriminal groups to cloak malware. The service employs advanced techniques such as…

    8 articles · Updated July 20, 2026
  • XLoader Malware Enhances Obfuscation and C2 Traffic Concealment

    XLoader malware has undergone significant upgrades, with its latest version 8.1 introducing advanced obfuscation techniques that complicate detection and analysis. The malware now masks its command-and-control (C2)…

    4 articles · Updated April 1, 2026
  • Makop Ransomware Enhancements Target Indian Organizations

    The Makop ransomware, a variant of the Phobos family, has been updated to include GuLoader malware for enhanced payload delivery. Recent attacks have primarily targeted Indian businesses, utilizing Remote Desktop…

    4 articles · Updated December 11, 2025
  • Rise of AI-Driven Ransomware: ESET Reports on PromptLock

    ESET's Threat Report for H2 2025 reveals the emergence of AI-driven malware, specifically PromptLock, the first known AI-driven ransomware capable of generating malicious scripts in real-time. This development marks a…

    2 articles · Updated December 16, 2025

Recent Intelligence Reports

  • Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service — Proofpoint · July 20, 2026
  • Formbook infostealer deployed in clandestine phishing campaigns | brief — Scworld · April 21, 2026
  • Formbook Malware Campaign Uses Multiple Obfuscation Techniques to Avoid Detection — Infosecurity-Magazine · April 20, 2026
  • XLoader Malware Upgrades Obfuscation Tactics and Hides C2 Traffic Behind Decoy Servers — Cybersecuritynews · April 1, 2026
  • XLoader malware Sharpens Obfuscation, Masks C2 Traffic via Decoy Servers — Gbhackers · April 1, 2026
  • ESET Threat Report H2 2025 — Feeds.Feedburner · December 16, 2025
  • Makop ransomware: GuLoader and privilege escalation in attacks against Indian businesses — Acronis · December 8, 2025
  • Beating XLoader at Speed: Generative AI as a Force Multiplier for Reverse Engineering — Research.Checkpoint · November 3, 2025

CVSS v3.1 Breakdown