TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Infosecurity Magazine

Formbook Malware Campaign Uses Multiple Obfuscation Techniques to Avoid Detection

2026-04-20 · Read original ↗

ATT&CK techniques detected

7 predictions
T1574.001DLL
77%
“common forms of business emails. “ what makes these campaigns especially noteworthy is not just the malware itself, but the diversity of methods used to evade detection and abuse legitimate software and trusted system processes, ” said watchguard. dll sideloading and obfuscated j…”
T1059.001PowerShell
71%
“but this time the malicious payload is hidden inside javascript and pdf files, which uses obfuscated code to help it hide from detection. when executed, the javascript drops two image files, which in turn drop powershell commands, obfuscated within long strings of code, which are…”
T1204.002Malicious File
70%
“but this time the malicious payload is hidden inside javascript and pdf files, which uses obfuscated code to help it hide from detection. when executed, the javascript drops two image files, which in turn drop powershell commands, obfuscated within long strings of code, which are…”
T1566.001Spearphishing Attachment
61%
“common forms of business emails. “ what makes these campaigns especially noteworthy is not just the malware itself, but the diversity of methods used to evade detection and abuse legitimate software and trusted system processes, ” said watchguard. dll sideloading and obfuscated j…”
T1204.002Malicious File
36%
“common forms of business emails. “ what makes these campaigns especially noteworthy is not just the malware itself, but the diversity of methods used to evade detection and abuse legitimate software and trusted system processes, ” said watchguard. dll sideloading and obfuscated j…”
T1566.002Spearphishing Link
34%
“formbook malware campaign uses multiple obfuscation techniques to avoid detection two phishing campaigns, each using a different stealthy infection technique, are targeting organizations in attacks which aim to deliver data stealing malware to devices running on microsoft windows…”
T1055.001Dynamic-link Library Injection
31%
“but this time the malicious payload is hidden inside javascript and pdf files, which uses obfuscated code to help it hide from detection. when executed, the javascript drops two image files, which in turn drop powershell commands, obfuscated within long strings of code, which are…”

Summary

Formbook attacks use combination of DLL Side-Loading and Obfuscated JavaScript to stay hidden, researchers at WatchGuard have uncovered