Threat actors are exploiting weaponized Excel spreadsheets to deliver the notorious FormBook information-stealer malware to Windows systems worldwide.
FortiGuard Labs has reported a recent campaign focused on users running outdated Microsoft Office applications, utilizing a known vulnerability (CVE-2017-0199) in OLE (Object Linking and Embedding) functionality.
This high-severity threat allows attackers to gain access to sensitive data, including credentials, keystrokes, and clipboard content, posing severe risks to organizations with inadequate patch management processes.
FormBook Payload Targets Legacy Office Versions
The attack commences with phishing emails masquerading as legitimate sales orders, enticing the recipient to open the attached Excel file.

Designed to exploit CVE-2017-0199, the attachment takes advantage of a logic flaw present in Microsoft Office 2007 through 2016.
When victims open these documents, the compromised Office software issues an HTTP request to a remote server, retrieving a malicious HTA (HTML Application) file.
The attack chain leverages COM objects to invoke mshta.exe, executing the malicious script without requiring further user interaction.
Upon successful exploitation, the HTA file’s payload encoded in base64 is decoded to download an executable, “sihost.exe,” into the infected machine’s %APPDATA% directory.

Static and dynamic analysis revealed that this file contains a resource named “SCRIPT,” which is decrypted at runtime.
Notably, the malware checks for the presence of debuggers via the IsDebuggerPresent API, incorporating anti-analysis mechanisms to thwart researchers.
Phishing Campaign Leverages Malicious Email
Next, the campaign’s payload extracts a secondary component named “springmaker” to the %TEMP% folder, where it is decrypted using an XOR operation with a hardcoded key (“3NQXSHDTVT2DPK06”).
The decrypted result is the ultimate payload FormBook malware. FormBook is well-known for its wide-ranging information-stealing capabilities, including harvesting credentials from browsers, logging keystrokes, capturing screenshots, and exfiltrating clipboard contents.
This campaign highlights the persistent risk posed by legacy vulnerabilities. Despite CVE-2017-0199 being patched for over eight years, many organizations have yet to update or decommission affected Office installations, due to factors like legacy system dependencies, resource constraints, and overlooked patch management.
As a result, unpatched environments remain highly susceptible to exploitation by even moderately sophisticated attackers.
Security researchers emphasize the critical importance of robust patch management, especially for commonly targeted productivity software.
In this instance, the attackers’ multi-stage approach phishing, exploitation, script execution, and lateral movement demonstrates the evolving sophistication of threat campaigns.
Fortinet notes that its customers are protected by layers of anti-phishing, web filtering, IPS, and antivirus signatures, but recommends ongoing vigilance, awareness training, and the immediate application of available security updates.
Organizations are urged to review endpoint protection controls, audit patching status on all Office deployments, and educate users about the risks of email attachments originating from external sources.
As the threat landscape continues to evolve, defenders must remain proactive to mitigate the risks of malware like FormBook.
Indicators of Compromise (IOCs)
| Artifact | Type | Value / SHA-256 |
|---|---|---|
| Malicious Excel Document | SHA-256 | 33A1696D69874AD86501F739A0186F0E4C0301B5A45D73DA903F91539C0DB427 |
| HTA Payload | SHA-256 | 2BFBF6792CA46219259424EFBBBEE09DDBE6AE8FD9426C50AA0326A530AC5B14 |
| Dropped Executable | SHA-256 | 7E16ED31277C31C0370B391A1FC73F77D7F0CD13CC3BAB0EAA9E2F303B6019AF |
| Secondary Payload | SHA-256 | A619B1057BCCB69C4D00366F62EBD6E969935CCA65FA40FDBFE1B95E36BA605D |
| FormBook (decrypted) | SHA-256 | 3843F96588773E2E463A4DA492C875B3241A4842D0C087A19C948E2BE0898364 |
| Malicious URL 1 | URL | hxxp[:]//172[.]245[.]123[.]32/xampp/hh/wef[.]hta |
| Malicious URL 2 | URL | hxxp[:]//172[.]245[.]123[.]32/199/sihost[.]exe |
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Update