216.73.217.22

FormBook Malware Uses Phishing, DLL Side-Loading, JavaScript

· Published 22/04/2026 12:43 · Modified 22/04/2026 15:32

Export JSON

Essential information

Published
22/04/2026 12:43
Modified
22/04/2026 15:32
Tags
2026-04-22 data-stealing dll side-loading formbook mandark mandark loader ntdll mapping obfuscated javascript panthomvai phishing campaigns syscall evasion
Related entities
1 observables, 17 techniques (mitre), 3 malware, 4 others

Description

Two distinct have been identified targeting companies in Greece, Spain, Slovenia, Bosnia and Central American countries to deliver malware. The first campaign uses RAR attachments containing legitimate executables like Sandboxie ImBox.exe, TikTok desktop, Adobe PDF Preview Handler, and XZ Utils, exploiting with malicious DLL files. The second campaign deploys heavily that drops encrypted PNG files, uses PowerShell with Base64 encoding, and leverages a custom .NET loader called to inject the payload into RegAsm process. Both campaigns deliver the same executable that employs advanced evasion by manually mapping ntdll.dll in memory to bypass user-mode monitoring and perform direct syscalls, enabling credential theft and data collection from browsers while avoiding detection mechanisms.

External references