FormBook is a Windows information-stealing trojan, also referred to as XLoader in later iterations. Active since at least 2016, it is used to steal credentials from web browsers, FTP applications, and the Windows Credential Manager, and supports keylogging, clipboard theft, and form grabbing. FormBook variants use HTTP(S)-based command-and-control communications and transmit collected data through POST requests. The malware has employed encrypted command-and-control infrastructure and code decryption to hinder analysis. Observed executions have established persistence and injected into legitimate Windows processes; FormBook has also used section-mapping-based process injection with SEC_IMAGE. FormBook is commonly distributed through phishing and malspam using business-themed lures and malicious archives or attachments. Campaigns have exploited Microsoft Office vulnerabilities including CVE-2017-11882 and CVE-2021-40444 to execute payloads. It has targeted organizations across sectors, including manufacturing firms, and has been repeatedly observed in Italian-language malspam campaigns. No single threat actor can be reliably attributed to FormBook activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Elastic tracked a FORMBOOK information-stealing campaign leveraging the MSHTML remote code exploit (CVE-2021-40444). Attackers used malicious Microsoft Office documents with externally linked MHTML OLE objects and ActiveX controls to achieve remote code execution and load subsequent payloads. | The Elastic Intelligence & Analytics team is tracking a new FORMBOOK information-stealing campaign leveraging the MSHTML remote code exploit (CVE-2021-40444).
Trend Micro uncovered a malicious Rich Text Format (RTF) file exploiting CVE-2017-11882 to deliver the spyware Loki (TSPY_LOKI). ... CVE-2017-11882 is a 17-year old memory corruption issue in Microsoft Office ... The flaw resides within Equation Editor (EQNEDT32.EXE) ... A proof-of-concept exploit was released publicly, but this has been fixed by Microsoft’s November Patch Tuesday. | Trend Micro’s initial and ongoing analysis also found that a spammer group is also actively exploiting CVE-2017-11882 to infect systems with information stealers Pony/FAREIT and FormBook.
It was also observed in 2018, distributed via emails with DOCX files that contained a URL. This URL downloaded an RTF file that exploits CVE-2017-8570 and drops an executable. This executable downloads the Formbook sample. | Formbook is an infostealer that has been advertised for sale in public hacking forums since February 2016... It is more advanced than a keylogger as it can retrieve authorization and login credentials from a web data form before the information reaches a secure server, bypassing HTTPS encryption.
Until recently, FormBook mostly exploited CVE-2017-0199, but newer FormBook variants used the recent Office 365 zero-day vulnerability, CVE-2021-40444. | Trend Micro detected a new campaign using a recent version of the known FormBook malware, an infostealer that has been around since 2016. ... newer FormBook variants used the recent Office 365 zero-day vulnerability, CVE-2021-40444.
The analytic detects a Microsoft Office product spawning the Windows msdt.exe process... Annotations ... CVE CVE-2022-30190 ... Associated Analytic Story ... Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190 ... https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability | References https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/trojanized-onenote-document-leads-to-formbook-malware/
BITTER has exploited Microsoft Office vulnerabilities... CVE-2018-0798...
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These campaigns, detailed in our previous report, distributed payloads that included AgentTesla, Formbook, Lokibot, Netwire and Betabot.
...the delivered payload is in favor of publicly sold malware such as NanoCore, Formbook, etc...
XLoader and FakeSpy are two of the most prevalent malware families that emerged from the mobile threat landscape recently. We first reported about XLoader in April 2018 when it used Domain Name System (DNS) cache poisoning/DNS spoofing to victimize users with malicious Android apps that steal PII and financial data and install additional apps.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The script job element directs Windows Script Host to spawn a shell that spawns a hidden PowerShell process which runs a Base64 encoded PowerShell script.
Pope.txt contained JavaScript code using variable renaming and string obfuscation. Profile.html also contained obfuscated JavaScript and ActiveXObjects.
Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
« bin.exe est téléchargé [...] puis injecté dans ROUTE.EXE et autochk.exe. »
Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
Данный метод незаслуженно остаётся в тени упомянутого выше. В его основе лежит NtMapViewOfSection() из либы Ntdll.dll, которая используется малварью для скрытой инъекции кода в обход EDR. Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
Pope.txt contained JavaScript code using variable renaming and string obfuscation. The PowerShell command was Base64 encoded, and Profile.html contained obfuscated JavaScript.
1.doc.inf has the .inf extension, but is actually a DLL file. Profile.rar had a RAR extension but contained raw data with a WSH-interpretable script-job element prepended.
« bin.exe est téléchargé [...] puis injecté dans ROUTE.EXE et autochk.exe. »
Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
Данный метод незаслуженно остаётся в тени упомянутого выше. В его основе лежит NtMapViewOfSection() из либы Ntdll.dll, которая используется малварью для скрытой инъекции кода в обход EDR. Технику применяют сл.вредоносы - все они мапят свои либы с атрибутом SEC_IMAGE для загрузки пайлоада
1,373 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information stealer deployed after initial access through a malicious PDF and batch file. It establishes web-based C2 across numerous domains using four-character URI paths and an Android-spoofed user agent, and targets credentials and data associated with banking and brokerage portals for exfiltration, including via Sendspace.
Password-stealing malware distributed in Italian malspam campaigns using order and quotation lures.
Credential-stealing form-grabber deployed through process injection. It conducted high-volume HTTP(S) C2 using four-character URI paths and a spoofed Android user agent, swept browser sessions for banking and brokerage credentials, and staged/exfiltrated collected data through Sendspace.
A password-stealing malware family distributed through Italian-language malspam.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.