Researchers documented multiple XLoader/Formbook delivery chains that used different initial access methods but converged on the same information-stealing malware. One campaign used spam emails with PDF attachments that led victims through embedded XLSX and downloaded RTF files, while another impersonated SharePoint to push users to a malicious ZIP archive. A separate Excel-based campaign exploited CVE-2017-11882 in Microsoft Equation Editor (EQNEDT32.exe) through a malicious OLE object, triggering shellcode that downloaded and launched additional malware from attacker-controlled infrastructure.
Across the campaigns, the loaders relied on layered obfuscation, in-memory execution, and repeated process injection before deploying the final XLoader payload. Analysts observed AutoIT-based loaders, anti-analysis delays, CRC32 API hashing, shellcode injection into processes including svchost.exe, netsh.exe, and explorer.exe, and payload components hidden in bitmap resources and unpacked with steganography or decompression routines. The final malware established persistence through HKCU Run keys and shortcut artifacts, used process hollowing, and stole credentials, cookies, keystrokes, clipboard contents, and screenshots while maintaining command-and-control channels that could fetch additional payloads or remove the malware.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Sublime analyzed and blocked a phishing email impersonating SharePoint that linked to a ZIP archive containing an AutoIT executable. The researchers assessed with high confidence that the final payload was XLoader/Formbook and with moderate confidence that the initial loader components were related to TrickGate, based on shellcode behavior, API hashing, staged injection, and PKT2-related C2 strings.
FortiGuard Labs reported a malicious Excel file, "GAT412-IFF22.xlsx," that auto-loaded an embedded OLE object and exploited CVE-2017-11882 in EQNEDT32.EXE to download and run a payload from lutanedukasi[.]co[.]id. The report also described a related Delphi-based Formbook loader that used a bitmap resource, Discord CDN payload retrieval, process hollowing, and Run-key persistence.
Cyble Research Labs analyzed a spam-driven infection chain in which a malicious PDF dropped an XLSX file that fetched an RTF exploiting CVE-2017-11882 to deliver Xloader. The report detailed the .NET loader stages, steganography in a bitmap resource, process hollowing, persistence, and Xloader's credential theft and C2 capabilities.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 117 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
sublime.security
Open sourcefortinet.com
Open sourceblog.cyble.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.