That Fake Purchase Order in Your Inbox? It Might Be Formbook Stealing Every Keystroke You Type
This article was originally published on ThreatChain — decentralized threat intelligence. A commodity stealer hiding in phishing attachments. Here's the full picture. Imagine you work at a mid-size...

Source: DEV Community
This article was originally published on ThreatChain — decentralized threat intelligence. A commodity stealer hiding in phishing attachments. Here's the full picture. Imagine you work at a mid-sized company. It's a Tuesday morning. You open your email and see a message with the subject line "PO-000806758" — a purchase order. Maybe it's from a supplier you've been waiting on. The attachment is an .exe file, but it looks like a standard document. You double-click. Nothing dramatic happens. No skull-and-crossbones, no ransom note. Your screen doesn't even flicker. But from that moment on, every password you type, every form you fill out, every credit card number you enter into a browser — all of it is being silently copied and sent to someone you've never met. That's Formbook. And this is a real sample spotted in the wild this April. What Is Formbook, Exactly? Formbook is one of the most popular and long-running information stealers in the world. Think of it as a silent spy that moves int