FormBook, also widely associated with the XLoader name, is a long-running malware-as-a-service infostealer focused on harvesting sensitive user and system data from Windows systems. It is known for stealing keystrokes, clipboard contents, and data entered into web forms, and has been repeatedly described as a form-grabber and password stealer used in broad criminal campaigns as well as more targeted phishing operations. FormBook has remained prevalent for years and continues to appear in commodity malware ecosystems, often alongside other stealers and remote-access malware.
FormBook is commonly delivered through phishing and malspam campaigns, including business-themed lures carrying archived attachments, script files, Office documents, ZIP archives, or batch files. It has also been observed in spearphishing operations targeting specific organizations, including maritime-sector victims, and in campaigns using malvertising or compromised websites with ClickFix-style social engineering. In addition to direct delivery, FormBook is frequently deployed by intermediary loaders and downloaders, including malware families and loader clusters that distribute multiple commodity payloads.
Technically, analyzed samples show layered obfuscation and multi-stage unpacking, including Base64 encoding, decompression, reversed strings or content, embedded PE extraction, and .NET-based staging. Some campaigns and related delivery chains use steganographic concealment or image-embedded payloads to hinder detection. FormBook-associated tradecraft has also included process injection or abuse of legitimate Windows-related processes for payload launch and evasion. Recent reporting notes continued evolution in obfuscation and anti-analysis measures, indicating sustained operator investment in making sampling and reverse engineering more difficult.
Observed capabilities include keylogging, clipboard theft, collection of web form data, and exfiltration of stolen information and host details to attacker-controlled infrastructure. Some analyzed samples also exfiltrated system information and the victim’s public IP address. FormBook is sold and operated under a malware-as-a-service model, which has contributed to its widespread use across opportunistic cybercrime campaigns and targeted credential-theft operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2017-11882 ... Products Associated Malware: Loki, FormBook, Pony/FAREIT | CVE-2017-11882 Vulnerable Products: Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 Products Associated Malware: Loki, FormBook, Pony/FAREIT Mitigation: Update affected Microsoft products with the latest security patches | CVE-2017-11882 ... Associated Malware: Loki, FormBook, Pony/FAREIT | CVE-2017-11882 Vulnerable Products: Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 Products Associated Malware: Loki, FormBook, Pony/FAREIT
BITTER has exploited Microsoft Office vulnerabilities... CVE-2018-0798...
Cisco Talos has been tracking a new campaign involving the FormBook malware since May 2018... FormBook is an inexpensive stealer available as "malware as a service." ... It is able to record keystrokes, steal passwords (stored locally and in web forms) and can take screenshots.
The analytic detects a Microsoft Office product spawning the Windows msdt.exe process... may indicate an attempt to exploit protocol handlers to bypass security controls... Associated Analytic Story: Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190.
The following analytic detects Office products writing .cab or .inf files, indicative of CVE-2021-40444 exploitation. This activity is significant as it may signal an attempt to load malicious ActiveX controls and download remote payloads, a known attack vector. | https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/trojanized-onenote-document-leads-to-formbook-malware/
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...families of RATs and infostealers. These included Lokibot, Betabot, Formbook, and AgentTesla."
29 distinct techniques documented for this family, organized by ATT&CK tactic.
This script acts as a downloader, retrieving and executing a PowerShell script.
At the end, I managed to extract the malware configuration, as shown in Figure 11. These details are essential for the malware to work properly and contain sensitive data such as Smtp sender, receiver and password.
In most of the cases observed at the time of writing this article, PhantomVAI Loader injected the payload into the Microsoft Build Engine executable, MSBuild.exe.
Upon execution, these files kick off a multi-stage chain of extracting, deobfuscating, loading and executing secondary payloads (dynamic-link libraries), eventually detonating the final payload (executable).
"addinprocess32.exe... can be used for injection and launching malicious payloads"; "These events are typical for injecting code into a process. Virtual protect can be abused by malware authors to modify memory protection and writing bytes to an area in memory is typical in process injection techniques."
After downloading and extracting the .bat file, we observed a relatively simple obfuscation technique — Base64 encoding.
stegocampaign is a cyberattack using steganography to hide malware in images, making detection difficult.
Other campaigns have impersonated brands like Adobe, Gimp, Slack, Tor, and Thunderbird, in order to infect users with AuroraStealer, RedLine, Vidar, FormBook, and more.
"addinprocess32.exe... can be used for injection and launching malicious payloads"; "These events are typical for injecting code into a process. Virtual protect can be abused by malware authors to modify memory protection and writing bytes to an area in memory is typical in process injection techniques."
In most of the cases observed at the time of writing this article, PhantomVAI Loader injected the payload into the Microsoft Build Engine executable, MSBuild.exe.
This was easily decoded using CyberChef as shown in Figure 3 + 4.
"The actor in this case has utilized a commonly abused LOLBIN (Living Off The Land Binary) here to execute the encoded script through ‘DeviceCredentialDeployment.exe’ in an attempt to avoid detection"; "another Living Off the Land technique for injection/execution... pass in arguments for the process ‘addinprocess32.exe’"
While debugging this new and final staged malware, it was observed that it is using a lot of keylogging techniques and sending information to the attacker.
While debugging this new and final staged malware, it was observed that it is using a lot of keylogging techniques and sending information to the attacker.
Formbook and XLoader disguise real C2 traffic among smokescreen HTTP requests with encoded and encrypted content to multiple domains, randomly selected from an embedded list.
XLoader Activity ... C2 for data exfiltration ... hxxp[://]www.sixfiguredigital[.]group/aoc3/
A campaign is marked by an identifier that is present in HTTP POST and GET requests issued by the malware.
352 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
175 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
FormBook7
FormBook7
A long-running infostealer sold as malware-as-a-service. In this campaign it was delivered through spear phishing emails impersonating maritime supply chain companies and used against a South Korean maritime manufacturer.
Mentioned as another malware family previously or likely delivered by similar campaigns, specifically as an infostealer alternative payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.