FormBook is a long-running Windows information-stealing malware family widely sold under a malware-as-a-service model and commonly used in financially motivated cybercrime. It is primarily associated with credential theft and surveillance of user input, including keylogging, clipboard capture, and theft of data entered into web forms and browsers. FormBook has repeatedly appeared in commodity malware campaigns and targeted phishing operations, including business-themed email lures carrying archive attachments or script-based payloads. It has also been delivered by other malware services and loaders, including crypter and downloader ecosystems such as Cruciferra and GuLoader, and has appeared in campaigns targeting sectors such as maritime shipping and organizations in Italy through recurring malspam waves.
Observed FormBook infection chains show heavy use of obfuscation and staged execution. Samples have been delivered as batch scripts, archives, and ZIP attachments, with intermediate loaders unpacking embedded executables and DLLs before launching the final payload. Analysis of samples indicates use of process injection-related execution techniques in some chains. Once active, FormBook steals system information and exfiltrates collected data to attacker-controlled infrastructure. Its operational role in campaigns is consistently that of an infostealer rather than a general-purpose remote administration tool.
FormBook is frequently clustered with other commodity stealers and RATs such as Agent Tesla, Remcos, XLoader, AsyncRAT, and XWorm, reflecting its role in shared cybercrime distribution ecosystems. XLoader is closely associated with FormBook and is often treated as part of the same lineage or ecosystem in reporting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2017-11882 ... Products Associated Malware: Loki, FormBook, Pony/FAREIT | CVE-2017-11882 Vulnerable Products: Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 Products Associated Malware: Loki, FormBook, Pony/FAREIT Mitigation: Update affected Microsoft products with the latest security patches | CVE-2017-11882 ... Associated Malware: Loki, FormBook, Pony/FAREIT | CVE-2017-11882 Vulnerable Products: Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 Products Associated Malware: Loki, FormBook, Pony/FAREIT
BITTER has exploited Microsoft Office vulnerabilities... CVE-2018-0798...
Cisco Talos has been tracking a new campaign involving the FormBook malware since May 2018... FormBook is an inexpensive stealer available as "malware as a service." ... It is able to record keystrokes, steal passwords (stored locally and in web forms) and can take screenshots.
The analytic detects a Microsoft Office product spawning the Windows msdt.exe process... may indicate an attempt to exploit protocol handlers to bypass security controls... Associated Analytic Story: Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190.
The following analytic detects Office products writing .cab or .inf files, indicative of CVE-2021-40444 exploitation. This activity is significant as it may signal an attempt to load malicious ActiveX controls and download remote payloads, a known attack vector. | https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/trojanized-onenote-document-leads-to-formbook-malware/
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...families of RATs and infostealers. These included Lokibot, Betabot, Formbook, and AgentTesla."
29 distinct techniques documented for this family, organized by ATT&CK tactic.
This script acts as a downloader, retrieving and executing a PowerShell script.
At the end, I managed to extract the malware configuration, as shown in Figure 11. These details are essential for the malware to work properly and contain sensitive data such as Smtp sender, receiver and password.
In most of the cases observed at the time of writing this article, PhantomVAI Loader injected the payload into the Microsoft Build Engine executable, MSBuild.exe.
Upon execution, these files kick off a multi-stage chain of extracting, deobfuscating, loading and executing secondary payloads (dynamic-link libraries), eventually detonating the final payload (executable).
"addinprocess32.exe... can be used for injection and launching malicious payloads"; "These events are typical for injecting code into a process. Virtual protect can be abused by malware authors to modify memory protection and writing bytes to an area in memory is typical in process injection techniques."
After downloading and extracting the .bat file, we observed a relatively simple obfuscation technique — Base64 encoding.
stegocampaign is a cyberattack using steganography to hide malware in images, making detection difficult.
Other campaigns have impersonated brands like Adobe, Gimp, Slack, Tor, and Thunderbird, in order to infect users with AuroraStealer, RedLine, Vidar, FormBook, and more.
"addinprocess32.exe... can be used for injection and launching malicious payloads"; "These events are typical for injecting code into a process. Virtual protect can be abused by malware authors to modify memory protection and writing bytes to an area in memory is typical in process injection techniques."
In most of the cases observed at the time of writing this article, PhantomVAI Loader injected the payload into the Microsoft Build Engine executable, MSBuild.exe.
This was easily decoded using CyberChef as shown in Figure 3 + 4.
"The actor in this case has utilized a commonly abused LOLBIN (Living Off The Land Binary) here to execute the encoded script through ‘DeviceCredentialDeployment.exe’ in an attempt to avoid detection"; "another Living Off the Land technique for injection/execution... pass in arguments for the process ‘addinprocess32.exe’"
While debugging this new and final staged malware, it was observed that it is using a lot of keylogging techniques and sending information to the attacker.
While debugging this new and final staged malware, it was observed that it is using a lot of keylogging techniques and sending information to the attacker.
Formbook and XLoader disguise real C2 traffic among smokescreen HTTP requests with encoded and encrypted content to multiple domains, randomly selected from an embedded list.
XLoader Activity ... C2 for data exfiltration ... hxxp[://]www.sixfiguredigital[.]group/aoc3/
A campaign is marked by an identifier that is present in HTTP POST and GET requests issued by the malware.
352 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
179 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family delivered as a payload by Cruciferra; described in the content as among the remote-access trojans and information stealers it distributes.
Loader malware ecosystem referenced because Blind Eagle's RunPE template appears copied or licensed from it.
A malware payload family observed being delivered by Cruciferra.
FormBook7
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.