FormBook is a long-running Windows infostealer sold through a malware-as-a-service model and widely used in cybercrime campaigns. It is primarily designed to steal sensitive information from infected systems, including keystrokes, clipboard contents, browser form data, and other system information, and it can exfiltrate collected data to attacker-controlled infrastructure. FormBook has been observed in targeted spearphishing as well as broad malspam operations, often using business-themed lures and archive, script, document, or batch-based delivery chains. It has also appeared in campaigns using steganographic or multi-stage loaders and is frequently delivered by third-party malware services and loaders such as GuLoader, MalVirt, and other commodity crypters.
Operationally, FormBook commonly appears as the final payload in layered infection chains that use obfuscation, embedded PE stages, and process injection or related execution techniques to evade analysis and detection. Reporting has linked it to campaigns targeting sectors including maritime shipping and logistics, as well as opportunistic campaigns affecting financial services, healthcare, government, and other industries. It is regularly distributed in phishing campaigns targeting users in multiple regions, including Italy and South Korea, and has been associated with broader criminal ecosystems that also distribute Agent Tesla, Remcos, AsyncRAT, XWorm, RedLine, and similar commodity malware.
Aliases and branding overlap with XLoader, which is widely treated as the later evolution or rebranding of the FormBook family. Across reporting, the family is consistently characterized as a credential- and information-stealing malware family focused on browser and user-input theft rather than destructive or ransomware activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2017-11882 ... Products Associated Malware: Loki, FormBook, Pony/FAREIT | CVE-2017-11882 Vulnerable Products: Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 Products Associated Malware: Loki, FormBook, Pony/FAREIT Mitigation: Update affected Microsoft products with the latest security patches | CVE-2017-11882 ... Associated Malware: Loki, FormBook, Pony/FAREIT | CVE-2017-11882 Vulnerable Products: Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 Products Associated Malware: Loki, FormBook, Pony/FAREIT
BITTER has exploited Microsoft Office vulnerabilities... CVE-2018-0798...
Cisco Talos has been tracking a new campaign involving the FormBook malware since May 2018... FormBook is an inexpensive stealer available as "malware as a service." ... It is able to record keystrokes, steal passwords (stored locally and in web forms) and can take screenshots.
The analytic detects a Microsoft Office product spawning the Windows msdt.exe process... may indicate an attempt to exploit protocol handlers to bypass security controls... Associated Analytic Story: Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190.
The following analytic detects Office products writing .cab or .inf files, indicative of CVE-2021-40444 exploitation. This activity is significant as it may signal an attempt to load malicious ActiveX controls and download remote payloads, a known attack vector. | https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/trojanized-onenote-document-leads-to-formbook-malware/
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...families of RATs and infostealers. These included Lokibot, Betabot, Formbook, and AgentTesla."
29 distinct techniques documented for this family, organized by ATT&CK tactic.
This script acts as a downloader, retrieving and executing a PowerShell script.
At the end, I managed to extract the malware configuration, as shown in Figure 11. These details are essential for the malware to work properly and contain sensitive data such as Smtp sender, receiver and password.
In most of the cases observed at the time of writing this article, PhantomVAI Loader injected the payload into the Microsoft Build Engine executable, MSBuild.exe.
Upon execution, these files kick off a multi-stage chain of extracting, deobfuscating, loading and executing secondary payloads (dynamic-link libraries), eventually detonating the final payload (executable).
"addinprocess32.exe... can be used for injection and launching malicious payloads"; "These events are typical for injecting code into a process. Virtual protect can be abused by malware authors to modify memory protection and writing bytes to an area in memory is typical in process injection techniques."
After downloading and extracting the .bat file, we observed a relatively simple obfuscation technique — Base64 encoding.
stegocampaign is a cyberattack using steganography to hide malware in images, making detection difficult.
Other campaigns have impersonated brands like Adobe, Gimp, Slack, Tor, and Thunderbird, in order to infect users with AuroraStealer, RedLine, Vidar, FormBook, and more.
"addinprocess32.exe... can be used for injection and launching malicious payloads"; "These events are typical for injecting code into a process. Virtual protect can be abused by malware authors to modify memory protection and writing bytes to an area in memory is typical in process injection techniques."
In most of the cases observed at the time of writing this article, PhantomVAI Loader injected the payload into the Microsoft Build Engine executable, MSBuild.exe.
This was easily decoded using CyberChef as shown in Figure 3 + 4.
"The actor in this case has utilized a commonly abused LOLBIN (Living Off The Land Binary) here to execute the encoded script through ‘DeviceCredentialDeployment.exe’ in an attempt to avoid detection"; "another Living Off the Land technique for injection/execution... pass in arguments for the process ‘addinprocess32.exe’"
While debugging this new and final staged malware, it was observed that it is using a lot of keylogging techniques and sending information to the attacker.
While debugging this new and final staged malware, it was observed that it is using a lot of keylogging techniques and sending information to the attacker.
Formbook and XLoader disguise real C2 traffic among smokescreen HTTP requests with encoded and encrypted content to multiple domains, randomly selected from an embedded list.
XLoader Activity ... C2 for data exfiltration ... hxxp[://]www.sixfiguredigital[.]group/aoc3/
A campaign is marked by an identifier that is present in HTTP POST and GET requests issued by the malware.
352 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
177 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader malware ecosystem referenced because Blind Eagle's RunPE template appears copied or licensed from it.
An infostealer observed being delivered by Cruciferra.
FormBook7
FormBook7
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.