Connect with us

CyberSecurity

Formbook Malware Campaign Exploits Multiple Obfuscation Techniques to Evade Detection

Published

on

Formbook Malware Campaign Exploits Multiple Obfuscation Techniques to Evade Detection

Cybercriminals have launched two distinct phishing campaigns, each employing a stealthy infection method, to target organizations running Microsoft Windows. The primary objective? To deploy Formbook, a notorious infostealer malware that has been a staple of malware-as-a-service operations since 2016.

Formbook is designed to harvest sensitive information—login credentials, browser data, and screenshots—while using advanced evasion techniques to slip past security tools. A decade after its debut, this threat remains active across industries, with no signs of slowing down.

How the Formbook Malware Campaign Works

Security researchers at WatchGuard have detailed two new Formbook campaigns in a blog post published on April 20. These attacks target companies in Greece, Spain, Slovenia, Bosnia, Croatia, and several South American countries. The phishing lures are disguised as routine business emails, making them hard to spot.

What sets these campaigns apart is the diversity of evasion methods. One relies on DLL sideloading, while the other uses obfuscated JavaScript. Both aim to deliver the same malicious payload: Formbook.

DLL Sideloading: A Classic Evasion Tactic

The first campaign starts with a phishing email containing an RAR file. Inside, there are four files: three dynamic-link libraries (DLLs) and one Windows executable (EXE). Attackers use DLL sideloading, a technique that tricks a legitimate program into loading a malicious DLL instead of a safe one. This allows the malware to run without triggering alarms.

This method is particularly effective because it abuses trusted system processes. Security teams often struggle to flag such behavior as suspicious, giving attackers a clear path to deploy Formbook.

Obfuscated JavaScript: A Modern Twist

The second campaign takes a different route. It also begins with a phishing email, but this time, the malicious payload hides inside JavaScript and PDF files. The code is heavily obfuscated to evade detection.

When executed, the JavaScript drops two image files. These images contain PowerShell commands, obfuscated within long strings of code. Ultimately, these commands run a Windows executable that deploys a custom malware loader. This loader has previously distributed other threats like Remcos, XWorm, AsyncRAT, and SmokeLoader. In this case, it delivers Formbook.

Why This Formbook Malware Campaign Matters

Formbook is not new, but its persistence and adaptability make it a serious concern. By using multiple obfuscation techniques, attackers can bypass traditional security measures. As a result, organizations must stay vigilant.

WatchGuard advises security teams to monitor for suspicious archive-based email attachments, anomalous DLL loading behavior, and PowerShell execution tied to user-opened attachments. They also recommend watching for signs of manual DLL mapping or direct syscall activity in memory.

Defending Against These Evasion Tactics

To counter these threats, companies should focus on behavior-based detection. Correlating activities across the attack chain—like email attachments, DLL loading, and PowerShell commands—can help identify Formbook infections before data is compromised.

Additionally, implementing robust email filtering and endpoint protection solutions can reduce the risk. Employee training on phishing awareness is also crucial, as these attacks often rely on human error.

Conclusion: Staying Ahead of Formbook

This Formbook malware campaign highlights the evolving nature of cyber threats. Attackers are constantly refining their methods, using DLL sideloading and obfuscated JavaScript to stay one step ahead. However, with the right security strategies, organizations can detect and stop these attacks.

By understanding how these evasion techniques work, security teams can better protect their networks. The key is to remain proactive, monitor for unusual behavior, and educate users about the risks of phishing.

CyberSecurity

Former Ransomware Negotiator Pleads Guilty to Aiding BlackCat Cyber Gang in Multimillion-Dollar Scheme

Published

on

Former Ransomware Negotiator Pleads Guilty to Aiding BlackCat Cyber Gang in Multimillion-Dollar Scheme

In a stunning betrayal of trust, a former ransomware negotiator pleads guilty to secretly colluding with the notorious BlackCat cyber gang. Angelo Martino, 41, from Land O’Lakes, Florida, admitted to one count of conspiracy to obstruct commerce by extortion, according to the U.S. Department of Justice. This case highlights a dark underbelly of the cybersecurity industry, where those hired to defend can become the attackers.

The Inside Job: How a Negotiator Turned Traitor

Martino, who worked for the incident response firm Digital Mint, began cooperating with the BlackCat ransomware group in April 2023. As a negotiator for five corporate ransomware victims, he had access to sensitive information—including insurance policy limits and internal negotiation strategies. Instead of protecting his clients, he passed these details to the cybercriminals, allowing them to maximize their extortion demands. The Justice Department confirmed that Martino was paid for this intelligence.

But his betrayal did not stop there. Martino also admitted to conspiring with Ryan Goldberg of Georgia and Kevin Martin of Texas to deploy ransomware against various U.S. victims between April and November 2023. This made him an active affiliate of the BlackCat group, directly participating in attacks rather than just facilitating them.

Multimillion-Dollar Extortion: The Scale of the Scheme

The financial impact of this conspiracy was staggering. Authorities have already seized $10 million in assets from Martino, including digital currency, vehicles, a food truck, and a luxury fishing boat. Court documents reveal that an unnamed hospitality firm paid a ransom of $16.5 million, a financial services firm paid $25.7 million, and a non-profit organization paid $26.8 million. Other victims spanned retailers, manufacturers, medical companies, engineering firms, and pharmaceutical companies.

Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division condemned the betrayal: “Angelo Martino’s clients trusted him to respond to ransomware threats and help thwart and remedy them on behalf of victims. Instead, he betrayed them and began launching ransomware attacks himself by assisting cybercriminals and harming victims, his own employer, and the cyber incident response industry itself.”

BlackCat Ransomware Group: A Persistent Threat

The BlackCat group, also known as ALPHV, has been one of the most prolific ransomware operations in recent years. The FBI estimated that the group made as much as $300 million from hundreds of victims up to late 2023. In one notorious incident, an affiliate threatened to report a victim to the U.S. Securities and Exchange Commission (SEC) to pressure payment—a tactic that underscores the group’s ruthlessness.

However, law enforcement struck back in December 2023, seizing the group’s leak site and releasing a decryptor for the ransomware. Experts believe this action may have saved victims tens of millions of dollars in ransom payments. Despite this, the case of Martino shows how deeply the tentacles of such groups can reach into the cybersecurity industry.

Legal Consequences and Lessons for the Industry

Martino will be sentenced on July 9 and faces a maximum penalty of 20 years in federal prison. This case serves as a stark warning to other cybersecurity professionals who might consider crossing ethical lines. It also raises critical questions about vetting processes and oversight within incident response firms.

For businesses, this incident underscores the importance of choosing trusted cybersecurity partners and implementing strict monitoring protocols. As ransomware attacks continue to evolve, the line between defender and attacker can blur—making vigilance more crucial than ever. To learn more about protecting your organization, explore our guide on cybersecurity best practices and tips for building a ransomware response plan.

In conclusion, the case of a ransomware negotiator pleading guilty to aiding the BlackCat cyber gang is a cautionary tale. It reminds us that trust must be earned and verified, especially in the high-stakes world of cyber extortion. As the sentencing date approaches, the cybersecurity community will be watching closely—hoping that justice serves as a deterrent for future betrayals.

Continue Reading

CyberSecurity

Kids Are Using Fake Mustaches to Bypass Age-Verification Systems—Here’s How

Published

on

Kids Are Using Fake Mustaches to Bypass Age-Verification Systems—Here’s How

It turns out that some age-verification systems are no match for a little creativity. According to a recent report from the U.K.-based nonprofit Internet Matters, children are drawing on fake mustaches with makeup pencils to slip past the digital gates of adult websites. This eyebrow-raising tactic is just one of several methods kids are using to defeat online age checks.

The report surveyed 1,000 children about their experiences with age-verification checks. Approximately half of the respondents said that these checks were easy to bypass. “Children demonstrated a clear awareness of how to bypass age checks, either through their own experiences or by hearing about methods from others,” the report states. It adds that “one technique brought up was children drawing facial hair on themselves so that the tools verifying them would think they were older, which was reported as working in multiple instances.”

How the Fake Mustache Trick Works

Age-verification systems often rely on facial recognition or real-time camera checks to estimate a user’s age. However, children have discovered that adding a simple accessory—like a drawn-on mustache—can fool these tools into thinking they are adults. This method exploits the algorithms’ reliance on visual cues associated with maturity, such as facial hair.

Building on this, other kids have found alternative bypasses. Some point their webcams at adult-looking characters in video games, while others simply pull obscure or funny faces. These workarounds highlight the fragility of current age-gating technology.

The Global Push for Age-Verification Laws

Age-verification laws are spreading rapidly worldwide, often promoted under the banner of online child safety. In the United States, half of all states have enacted some form of age-checking legislation. The United Kingdom has also implemented such laws, spurring a global trend. These regulations typically require adults to prove their age—usually by uploading a government-issued ID to a third-party service—before accessing adult content.

Critics, however, argue that these laws create databases vulnerable to hacking and leaks. They also warn that such measures threaten the open and decentralized nature of the internet. Companies like Apple have rolled out software updates to comply with these laws, while platforms like Reddit and Meta use a mix of ID uploads and algorithmic age estimation. Others, such as Discord, have delayed their rollouts due to user backlash and security concerns.

Why Current Age-Check Systems Are Failing

The fake mustache trick is not an isolated incident. As age-verification checks become more common, children are proving remarkably adept at finding loopholes. This suggests that many systems are not robust enough to handle determined users. The reliance on superficial visual cues makes them easy to manipulate.

Furthermore, the report indicates that kids share bypass methods among themselves, creating a cycle of circumvention. This raises questions about the effectiveness of these laws in achieving their stated goal of protecting minors. For more insights on online safety, check out our guide on keeping kids safe online.

What This Means for Parents and Policymakers

For parents, the takeaway is clear: age-verification systems are not foolproof. It is essential to have open conversations with children about online safety and the risks of adult content. For policymakers, the findings underscore the need for more sophisticated, privacy-preserving solutions. Relying on superficial checks like facial hair detection is not enough.

In addition, tech companies must invest in stronger verification methods that balance security with user privacy. As the landscape evolves, stay informed about the latest developments in digital age verification. Ultimately, the fake mustache trick serves as a wake-up call: current systems are failing, and a smarter approach is needed.

Continue Reading

CyberSecurity

Rise of Silent Subject Phishing: How Empty Email Subject Lines Are Targeting VIP Users

Published

on

Rise of Silent Subject Phishing: How Empty Email Subject Lines Are Targeting VIP Users

Cybercriminals are refining their tactics with a new wave of attacks that rely on a surprisingly simple trick: leaving the subject line blank. Known as silent subject phishing or null subject phishing, this technique is gaining traction among threat actors who target high-value individuals within organizations. According to a report from cybersecurity firm Cyberproof, these campaigns are designed to slip past traditional email defenses while exploiting human curiosity.

Instead of using suspicious keywords or urgent language that might trigger spam filters, attackers send emails with empty or vague subject fields. This approach reduces the amount of data available for detection engines to analyze, making it harder for machine learning models to flag the messages as malicious. The result? A higher chance that the email lands in the recipient’s inbox, ready to be opened.

How Silent Subject Phishing Bypasses Email Defenses

One of the main reasons behind the rise of silent subject phishing is its ability to evade conventional security controls. Many email filtering systems rely heavily on subject-line analysis to identify potential threats. By removing the subject entirely, attackers strip away a key signal that security tools use to assess risk. This forces organizations to depend on other detection methods, which may not be as robust.

Building on this, the emails often contain malicious links, QR codes, or attachments. These elements direct users to spoofed login pages or initiate malware downloads. In some cases, attackers encourage victims to scan QR codes with their personal mobile devices, where corporate monitoring tools are less effective. This shift to personal devices further complicates detection and response efforts.

Evasion Through Domain Rotation and URL Shortening

Attackers also rotate domains and payloads frequently to maintain campaign resilience. Shortened URLs are commonly used to obscure the final destination, bypassing URL filtering mechanisms. This makes it difficult for security teams to block malicious links before they reach users. As a result, the campaign can persist over time without being easily disrupted.

VIP Users in the Crosshairs: Why Executives Are Targeted

These campaigns frequently target executives, board members, and other privileged users. The reason is straightforward: a successful compromise of a VIP account can lead to significant data breaches, financial fraud, or lateral movement within the enterprise. Cyberproof observed that the activity spiked during the first quarter of 2026, with a 13.9% increase between January and February, followed by a further 7.0% rise in March. Projections suggest this upward trend will continue.

Therefore, organizations must recognize that VIP user phishing is not just a nuisance—it is a strategic threat. Attackers are willing to invest time and resources to craft campaigns that specifically target high-value individuals. The potential payoff from a single compromised executive account far outweighs the effort involved.

Abuse of Legitimate Tools and Phishing-as-a-Service Platforms

Alongside social engineering, the campaign leverages legitimate remote monitoring and management (RMM) software to blend malicious activity with routine IT operations. Cyberproof found variants of Datto RMM deployed under deceptive filenames. This allows attackers to establish persistence, execute commands, and exfiltrate sensitive data without raising immediate suspicion.

Additionally, a phishing-as-a-service (PaaS) toolkit known as FlowerStorm has been linked to the activity. This platform automates large-scale distribution and supports multi-stage attack chains. It enables threat actors to rapidly change tactics across different targets, making it harder for defenders to keep up.

Defending Against Silent Subject Phishing Attacks

To mitigate the risks posed by silent subject phishing, organizations need to move beyond subject-line filtering alone. A multi-layered approach is essential. Key measures include verifying full sender addresses for inconsistencies, avoiding unexpected attachments or links, and enforcing multi-factor authentication (MFA) across all accounts.

Furthermore, employee training is crucial. Users should be taught to recognize atypical phishing tactics, such as emails with no subject line or those that ask them to scan QR codes. Advanced email security solutions that inspect message content and behavior can also help detect malicious activity that simpler filters miss.

In conclusion, the findings from Cyberproof indicate a shift toward stealth-focused phishing operations. By using minimal content and trusted tools, attackers are achieving high success rates while evading detection. Organizations must adapt their defenses to address these evolving threats, especially when it comes to protecting their most valuable users.

Continue Reading

Trending