APTMembers
APT

TA505 Deploys Formbook via JS Dropper and Wildcard C2 in 35-Country Sweep

A 7 KB RAR attachment concealing a 71 KB JavaScript dropper is the entry point for an active TA505 credential-harvesting campaign tracked since June 2026. The dropper uses WMI execution and long-sleep evasion before beaconing to a disposable HTTPS domain backed by a wildcard Let's Encrypt certificate, ultimately delivering Formbook infostealer across ten industry verticals.

Jul 1, 2026, 21:58 (UTC+9)Last seenJul 1, 2026Severity77ByCTX TeamActorTA505Hive0065IOC6RegionsAEAUBGCACH

A seven-kilobyte RAR archive carrying a single JavaScript file — named to impersonate a routine trade document — is the opening move in an active credential-harvesting campaign that CTX Team has been tracking since early June 2026. The JavaScript dropper, weighing in at 71 KB and bearing the filename Swift_advise_40k$.js, invokes Windows Management Instrumentation for execution, deliberately stalls to outlast automated sandbox analysis, and then beacons over HTTPS to a disposable C2 domain…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence