FormBook Malware Uses Phishing, DLL Side-Loading, JavaScript
Reported 22 Apr 2026 by otx · Severity: medium
Two distinct phishing campaigns have been identified targeting companies in Greece, Spain, Slovenia, Bosnia and Central American countries to deliver FormBook data-stealing malware. The first campaign uses RAR attachments containing legitimate executables like Sandboxie ImBox.exe