FormBook is a long-running Windows information-stealing malware family sold under a malware-as-a-service model and also widely referred to in later activity as XLoader. It is primarily used to steal sensitive data from infected systems, including credentials and data entered into web forms, and it is also known for keylogging and clipboard monitoring. Reported variants and campaigns have additionally shown the ability to capture screenshots, download or stage additional payloads, and exfiltrate stolen information to attacker-controlled infrastructure.
FormBook is commonly distributed through phishing and malspam campaigns using business-themed lures such as invoices, quotations, requests, orders, bank transfers, shipping notices, and similar transactional pretexts. Observed delivery chains include archive attachments, script-based loaders, batch files, macro-enabled documents, and DLL sideloading. It has also appeared as a payload delivered by third-party malware-enablement services such as Cruciferra, which use layered obfuscation and defense-evasion techniques to deploy commodity stealers and RATs.
Behavior associated with FormBook includes heavy obfuscation or packing, anti-analysis measures, and process injection to hinder detection and improve execution reliability. Public reporting consistently characterizes it as a commodity infostealer focused on harvesting user data from Windows endpoints rather than destructive effects. It has been used in broad opportunistic phishing operations as well as more targeted spearphishing activity, including campaigns against business users and maritime-sector organizations. Frequent appearance in weekly malspam telemetry and sandbox rankings indicates that it remains an active and widely circulated stealer in the cybercrime ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Formbook ... older waves exploited CVE-2017-11882 in Microsoft Equation Editor via malicious Word documents. AgentTesla ... is chiefly delivered through phishing emails exploiting Microsoft Office vulnerabilities CVE-2017-11882 and CVE-2017-8570. Common Vulnerabilities Exploited (CVEs) ... CVE-2017-11882 Microsoft Equation Editor stack buffer overflow (RCE) AgentTesla, Formbook | Formbook is a long-running data stealer and form-grabber sold as MaaS since 2016, capable of keylogging, screenshot capture, credential theft, and staging additional malware.
BITTER has exploited Microsoft Office vulnerabilities... CVE-2018-0798...
Cisco Talos has been tracking a new campaign involving the FormBook malware since May 2018... FormBook is an inexpensive stealer available as "malware as a service." ... It is able to record keystrokes, steal passwords (stored locally and in web forms) and can take screenshots.
The analytic detects a Microsoft Office product spawning the Windows msdt.exe process... may indicate an attempt to exploit protocol handlers to bypass security controls... Associated Analytic Story: Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190.
The following analytic detects Office products writing .cab or .inf files, indicative of CVE-2021-40444 exploitation. This activity is significant as it may signal an attempt to load malicious ActiveX controls and download remote payloads, a known attack vector. | https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/trojanized-onenote-document-leads-to-formbook-malware/
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...families of RATs and infostealers. These included Lokibot, Betabot, Formbook, and AgentTesla."
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Weekly report by TG Soft's CRAM, concerning Italian malspam campaigns... The campaigns in Italian analyzed by the TG Soft C.R.A.M. were grouped according to macro categories, obtained from the subject of the email message used for malware distribution (malspam).
followed by JS and BAT scripts that ultimately deploy Python-based loaders... extracting a malicious JavaScript loader
At the end, I managed to extract the malware configuration, as shown in Figure 11. These details are essential for the malware to work properly and contain sensitive data such as Smtp sender, receiver and password.
a csomagolás/obfuszkáció és az anti-analysis viselkedés
stegocampaign is a cyberattack using steganography to hide malware in images, making detection difficult.
a Budapesti Műszaki és Gazdaságtudományi Egyetem nevével és arculati elemeivel visszaélő
This was easily decoded using CyberChef as shown in Figure 3 + 4.
"The actor in this case has utilized a commonly abused LOLBIN (Living Off The Land Binary) here to execute the encoded script through ‘DeviceCredentialDeployment.exe’ in an attempt to avoid detection"; "another Living Off the Land technique for injection/execution... pass in arguments for the process ‘addinprocess32.exe’"
FormBook típusú infostealert tartalmaz , amely adatlopásra, billentyűnaplózásra, clipboard-monitorozásra
FormBook típusú infostealert tartalmaz , amely adatlopásra, billentyűnaplózásra, clipboard-monitorozásra
387 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
186 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
2025-09-05: XLoader (Formbook) infection
Historically tagged on older samples using the same FedEx AWB lure, but the article explicitly says those historical tags do not prove the 2026 ISO delivers the same payload.
Long-running MaaS data stealer and form-grabber capable of keylogging, screenshot capture, credential theft, and staging additional malware. Recent campaigns used phishing with RAR attachments, DLL sideloading, and obfuscated JavaScript in PDFs.
Commodity malware distributed via Cruciferra.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.