FormBook Malware Campaign Targets US & South Korean Defence Contractors

Important commercial industries in both the United States and South Korea are currently being targeted by the FormBook malware distribution campaign.

That is the warning by security specialists FireEye, which said the aerospace, defence contractor, and manufacturing sectors are being hit in the third quarter of this year.

It comes amid heightened tensions on the Korean peninsular, as North Korea defies United Nations sanctions and presses ahead with its nuclear program and highly aggressive missile tests over Japan.

FormBook Malware

The FireEye warning was made in a blog posting on the matter, in which is provided a full technical breakdown of the malware.

FireEye said the “significant” FormBook email campaigns is using a variety of distribution mechanisms to deliver the information-stealing FormBook malware.

These include attached PDFs files with download links, Microsoft Word and Excel documents containing malicious macros, and finally archive files (i.e. ZIP, RAR, ACE, ISOs) containing nasty EXE payloads.

According to FireEye, the PDF and .Doc and .Xls campaigns have mostly impacted the United States, whereas the Archive campaign has been mostly targetting both the US and South Korea.

The FormBook malware is described as data stealer and form grabber, but not a fully fledged piece of banking malware. It has been advertised in various hacking forums since early 2016. The hackers have even placed glossy adverts for the malware on the criminal forums.

It targets Windows-based systems (XP, Vista, 7, 8 and 10) and can be hosted for just $29 per week for the full malware package.

The way it works is the malware injects itself (via its various email campaigns) onto local machines. From there is burrows into various processes, and installs function hooks to log keystrokes, steal clipboard data, and mine data from HTTP sessions.

Loading ...

The malware has a definite mean streak, as it can also execute commands from a command and control (C2) server, such as download and execute other files, or start processes, perform shutdowns or reboots, and even steal cookies and local passwords.

The FormBook campaign has been detected by FireEye as running between 18 July and 17 August, and much of the activity was centred on South Korea and the United States, with the manufacturing sector bearing the brunt of the attack.

India and Germany have also been hit, although the UK seems to have escaped its attention, for now.

“While FormBook is not unique in either its functionality or distribution mechanisms, its relative ease of use, affordable pricing structure, and open availability make FormBook an attractive option for cyber criminals of varying skill levels,” said FireEye.

“In the last few weeks, FormBook was seen downloading other malware families such as NanoCore,” the security specialist warned. “The credentials and other data harvested by successful FormBook infections could be used for additional cyber crime activities including, but not limited to, identity theft, continued phishing operations, bank fraud and extortion.

Malware Campaigns

It should be noted that other malware campaigns have been targetting the US and South Korea of late.

In August for example Malwarebytes warned that the Cerber ransomware was being delivered to specific countries in Asia, most notably South Korea.

Indeed, it found that South Korea was the most impacted country amid a slew of ongoing malvertising campaigns.

Do you know all about security in 2017? Try our quiz!

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

Tesla Shares Surge On China Advanced Self-Driving Push

Tesla makes key advances toward advanced self-driving rollout in China as chief Elon Musk meets…

12 hours ago

UK Law Aims To Boost Security For ‘Smart’ Devices

New UK rules bring in basic security requirements for millions of internet-connected devices, aiming to…

13 hours ago

Alphabet Value Surges Over $2tn On Dividend Plan

Google parent Alphabet sees market capitalisation surge over $2tn on plan to over first-ever cash…

19 hours ago

Google Asks US Court To Dismiss Federal Adtech Case

Google asks Virginia federal court to dismiss case brought by US Justice Department and eight…

19 hours ago

Snap Sees Surge In Users, Ad Revenues

Snapchat parent Snap reports user growth, revenues in spite of tough competition, in what may…

20 hours ago

Shein Subject To Most Stringent EU Digital Rules

Quick-growing fast-fashion company Shein must comply with most stringent level of EU digital rules after…

20 hours ago