Formbook Phishing Adds Redundant Delivery Paths

Two separate phishing chains are giving Formbook more ways to land on Windows systems. The standard response misses the point: blocking one attachment type or one script path does not stop the other route from reaching the same credential-stealing payload. WatchGuard says the campaigns hit organizations in Greece, Spain, Slovenia, Bosnia, Croatia, and parts of South America. One chain uses DLL side-loading from an RAR attachment, and the other uses obfuscated JavaScript, with both designed to evade detection and deliver Formbook, which steals login credentials, browser data, and screenshots. The practical risk is persistence. When attackers can swap delivery methods without changing the payload, a single defensive control is easier to bypass and the same malware can keep reaching Windows users across different regions.

Part of the PlainSec briefing for 2026-04-20

Sources