FormBook Malware Uses Phishing, DLL Side-Loading, JavaScript

Reported 22 Apr 2026 by otx · Severity: medium

Two distinct phishing campaigns have been identified targeting companies in Greece, Spain, Slovenia, Bosnia and Central American countries to deliver FormBook data-stealing malware. The first campaign uses RAR attachments containing legitimate executables like Sandboxie ImBox.exe