Hackers Deploy Weaponized Excel Files Used to Deliver FormBook Malware to Windows Machines

Threat actors are exploiting weaponized Excel spreadsheets to deliver the notorious FormBook information-stealer malware to Windows systems worldwide.

FortiGuard Labs has reported a recent campaign focused on users running outdated Microsoft Office applications, utilizing a known vulnerability (CVE-2017-0199) in OLE (Object Linking and Embedding) functionality.

This high-severity threat allows attackers to gain access to sensitive data, including credentials, keystrokes, and clipboard content, posing severe risks to organizations with inadequate patch management processes.

FormBook Payload Targets Legacy Office Versions

The attack commences with phishing emails masquerading as legitimate sales orders, enticing the recipient to open the attached Excel file.

FormBook Malware
Example of the Phishing Email

Designed to exploit CVE-2017-0199, the attachment takes advantage of a logic flaw present in Microsoft Office 2007 through 2016.

When victims open these documents, the compromised Office software issues an HTTP request to a remote server, retrieving a malicious HTA (HTML Application) file.

The attack chain leverages COM objects to invoke mshta.exe, executing the malicious script without requiring further user interaction.

Upon successful exploitation, the HTA file’s payload encoded in base64 is decoded to download an executable, “sihost.exe,” into the infected machine’s %APPDATA% directory.

FormBook Malware
Base64-Encoded Payload on the Malicious HTA File

Static and dynamic analysis revealed that this file contains a resource named “SCRIPT,” which is decrypted at runtime.

Notably, the malware checks for the presence of debuggers via the IsDebuggerPresent API, incorporating anti-analysis mechanisms to thwart researchers.

Phishing Campaign Leverages Malicious Email

Next, the campaign’s payload extracts a secondary component named “springmaker” to the %TEMP% folder, where it is decrypted using an XOR operation with a hardcoded key (“3NQXSHDTVT2DPK06”).

The decrypted result is the ultimate payload FormBook malware. FormBook is well-known for its wide-ranging information-stealing capabilities, including harvesting credentials from browsers, logging keystrokes, capturing screenshots, and exfiltrating clipboard contents.

This campaign highlights the persistent risk posed by legacy vulnerabilities. Despite CVE-2017-0199 being patched for over eight years, many organizations have yet to update or decommission affected Office installations, due to factors like legacy system dependencies, resource constraints, and overlooked patch management.

As a result, unpatched environments remain highly susceptible to exploitation by even moderately sophisticated attackers.

Security researchers emphasize the critical importance of robust patch management, especially for commonly targeted productivity software.

In this instance, the attackers’ multi-stage approach phishing, exploitation, script execution, and lateral movement demonstrates the evolving sophistication of threat campaigns.

Fortinet notes that its customers are protected by layers of anti-phishing, web filtering, IPS, and antivirus signatures, but recommends ongoing vigilance, awareness training, and the immediate application of available security updates.

Organizations are urged to review endpoint protection controls, audit patching status on all Office deployments, and educate users about the risks of email attachments originating from external sources.

As the threat landscape continues to evolve, defenders must remain proactive to mitigate the risks of malware like FormBook.

Indicators of Compromise (IOCs)

ArtifactTypeValue / SHA-256
Malicious Excel DocumentSHA-25633A1696D69874AD86501F739A0186F0E4C0301B5A45D73DA903F91539C0DB427
HTA PayloadSHA-2562BFBF6792CA46219259424EFBBBEE09DDBE6AE8FD9426C50AA0326A530AC5B14
Dropped ExecutableSHA-2567E16ED31277C31C0370B391A1FC73F77D7F0CD13CC3BAB0EAA9E2F303B6019AF
Secondary PayloadSHA-256A619B1057BCCB69C4D00366F62EBD6E969935CCA65FA40FDBFE1B95E36BA605D
FormBook (decrypted)SHA-2563843F96588773E2E463A4DA492C875B3241A4842D0C087A19C948E2BE0898364
Malicious URL 1URLhxxp[:]//172[.]245[.]123[.]32/xampp/hh/wef[.]hta
Malicious URL 2URLhxxp[:]//172[.]245[.]123[.]32/199/sihost[.]exe

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Update

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories