FormBook Malware Distributed via Horus Protector Using Word Docs
Essential information
- Published
- 29/04/2025 08:41
- Modified
- 29/04/2025 09:00
- Tags
- 2025-04-29 CVE-2017-11882 formbook horus maldoc phishing
- Related entities
- 101 observables, 5 techniques (mitre), 1 malware, 1 others
Description
Forcepoint X-Labs researchers have identified a phishing campaign where attackers distribute the FormBook information-stealing malware using Horus Protector, a malware distribution service designed to evade detection. The campaign employs malicious Microsoft Word documents that exploit the CVE-2017-11882 vulnerability in the Equation Editor.