VB2018 paper: Inside Formbook infostealer

The Formbook information-stealing trojan has been spread by a number of recent

spam campaigns

. The malware was advertised in hacking forums as long ago as January 2016, but wasn’t written about until an

Arbor Networks


blog post

in September 2017.

The malware is a ‘form-grabber’, which means it intercepts data entered in website forms, regardless of the entry method, and can thus steal information even if a virtual keyboard or autofill are used.

At VB2018 in Montreal, Gabriela Nicolao, a researcher from

Deloitte

in Argentina, presented a short

paper

in which she looked at Formbook’s background and history and analysed a sample of the malware. Formbook may not be APT-grade malware, but its continuing spread means it can still be effective.

You can read Gabriela’s paper in both

HTML

and

PDF

format.

Formbook-fig5.png


Did you see we have opened the

Call for Papers

for VB2019 in London? Submit your abstract before 17 March for a chance to make it onto the programme of one of the most international threat intelligence conferences!


Posted

in

by

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *