Researchers analyzed two Formbook/XLoader delivery chains that show operators refreshing distribution methods while reusing the same infostealer core. One March 2026 sample used a three-layer AutoIt v3 wrapper that dropped an intermediate file named intersentimental into %TEMP%, decrypted it with the recoverable 20-byte XOR key WADEJD3GLJQWUK1CSRTG, and launched shellcode to hollow legitimate Windows processes with a reused Formbook payload. The sample combined anti-analysis techniques including dead-code-heavy AutoIt scripting, custom string obfuscation, fake .NET CLR metadata, empty imports, API hashing, anti-debug checks, and Formbook’s RC4/SHA1-based self-decryption, while exposed build artifacts pointed to operator OPSEC failures such as a XAMPP-based build path, use of the default Windows Administrator account, clustered build times, and static XOR key reuse.
A separate campaign delivered Formbook through a 38,000-line, 1.54 MB VBScript dropper that used WMI, PowerShell, steganography, and IPFS-hosted payloads to evade detection and resist takedown. The script launched a hidden PowerShell stage via Win32_Process.Create, fetched fake JPEG files from gateway.lighthouse.storage, extracted a reversed Base64-encoded .NET assembly hidden between custom markers, and invoked Fiber.Program.Main through reflection before creating a scheduled task and injecting the final payload into wscript.exe. Lure names such as KIZAD_WSP-2025-PRO.vbs suggest possible targeting of logistics, manufacturing, construction, or commercial organizations in the UAE or broader Gulf region.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-20, WatchGuard reported two FormBook phishing campaigns targeting organizations in parts of Europe and Latin/Central America. One used archive lures themed around orders or payments and abused Sandboxie-plus for DLL side-loading, while the other used an obfuscated JavaScript dropper, PowerShell, and a custom .NET loader to deploy FormBook.
On 2026-03-12, Breakglass Intelligence reported a separate Formbook infection chain built around a 38,000-line obfuscated VBScript dropper that used WMI, PowerShell, steganography, and IPFS-hosted payloads. The chain established persistence with a scheduled task and ultimately injected Formbook into wscript.exe, with lure naming suggesting possible targeting in the UAE or Gulf region.
In a report published on 2026-03-12, Breakglass Intelligence analyzed a March 2026 Formbook/XLoader sample using a three-layer chain: an AutoIt wrapper, an XOR-encrypted intermediate payload, and a reused Formbook core. The report also exposed operator OPSEC weaknesses including a XAMPP-based build path, default Administrator usage, clustered build times, static XOR key reuse, and released hashes, detections, and hunting artifacts.
The outer AutoIt v3 loader in the analyzed Formbook/XLoader chain was compiled on 2026-03-05. The wrapper dropped an XOR-encrypted intermediate payload, decrypted it with a recoverable 20-byte key, and launched shellcode for process hollowing into legitimate Windows processes.
Breakglass found that the decrypted Formbook core embedded in the March 2026 sample carried a compile timestamp of 2021-05-23, indicating operators reused an older base kit rather than rebuilding the malware core. This predates the newer delivery wrapper used in the 2026 activity.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 30 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
watchguard.com
Open sourceintel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.