XLoader

MITRE ATT&CK: S1207 View on attack.mitre.org

Aliases: Formbook, XLoader

First seen
2016-01-01 00:00:00
Malware type
credential-stealer, keylogger, spyware, trojan
Family
Malware family
Operating systems
windows
Related IoCs
16688 (15631 malicious)
Last IoC activity
2026-09-02 04:23:16
Profile updated
2026-07-07 14:38:01

Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical retail-and-hospitality technology-and-telecommunications

Context

XLoader is an infostealer malware in use since at least 2016. Previously known and sometimes still referred to as Formbook, XLoader is a Malware as a Service (MaaS) known for stealing data from web browsers, email clients and File Transfer Protocol (FTP) applications.

Recent IoC activity

15,676 malicious indicators in Maltiverse are attributed to XLoader (S1207). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample 874c6faee7e17445012c0f573c29dde997a71cc86e15fc3152a22365cf83bdf1 2026-09-03 3
file sample 8750d7bb299badc971fa5a607936d4feb49b584e70ba7dd8b874bd3a8cf13ac9 2026-09-03 2
file sample 876fbd2b5fb59bfdb8b09e09a99d3ff92428eddbbfd096af61364af56de20f0c 2026-09-03 3
file sample 8771179cb6f0488244c65cdfab07668bfaea4d0b28a77ee94879448662fde67e 2026-09-03 2
hostname pepeglass.com 2026-09-03 1
file sample Order90001685004pdf.rar 2026-09-03 1
file sample 6dd9cbb836647f0028f8569c5c1aa9594501dec9922e1f20c4b3b7ab43f3014f.zip 2026-09-03 1
hostname zjydl.com 2026-09-03 1
hostname lslhm.com 2026-09-03 1
hostname cloudymellows.com 2026-09-03 1
hostname apps-tv.com 2026-09-03 1
hostname italiangreyhounds.online 2026-09-03 1
hostname countryharvestcrafts.com 2026-09-03 1
hostname www.lute.xyz 2026-09-03 1
hostname www.cottonandquirkclothing.online 2026-09-03 1
hostname www.kairoloma.com 2026-09-03 1
hostname cocoding.net 2026-09-03 1
file sample file 2026-09-03 1
file sample 86564d4471500d3932d0afddc8a0a524982e6b7f3a70630d47e214d31bd166e5 2026-09-03 2
file sample 4b2621a8fec5428bcec870cac4e032f230d046a58107b1b84fda180dd905a691.rar 2026-09-03 1

Detection coverage

  • 7 YARA rules
  • 439 Sigma rules

Malware & tools used

  • Screen Capture (attack-pattern)
  • Credentials from Password Stores (attack-pattern)
  • Process Hollowing (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Steal Web Session Cookie (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Scheduled Task (attack-pattern)
  • AutoHotKey & AutoIT (attack-pattern)
  • Keylogging (attack-pattern)
  • File Deletion (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Virtualization/Sandbox Evasion (attack-pattern)
  • Clipboard Data (attack-pattern)
  • Native API (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Browser Session Hijacking (attack-pattern)
  • System Shutdown/Reboot (attack-pattern)
  • Debugger Evasion (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • System Checks (attack-pattern)
  • Web Protocols (attack-pattern)
  • Asynchronous Procedure Call (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)

Detection rules

  • SECUINFRA_MALWARE_Formbook_Filename_Stage_2 (yara-rule)
  • CAPE_Formhooka (yara-rule)
  • CAPE_Formconfa (yara-rule)
  • CAPE_Formhelper (yara-rule)
  • CAPE_Formconfb (yara-rule)
  • CAPE_Formbook (yara-rule)
  • MALPEDIA_Win_Formbook_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Osx.Xloader (report)
  • blog.malwarebytes.com — Osx Xloader Hides Little Except Its Main Purpose What We Learned In The Installation Process (report)
  • lac.co.jp — 20220307 002893 (report)
  • sentinelone.com — Detecting Xloader A Macos Malware As A Service Info Stealer And Keylogger (report)
  • zscaler.com — Technical Analysis Xloader Versions 6 And 7 Part 1 (report)
  • blogs.blackberry.com — Threat Thursday Xloader Infostealer (report)
  • vmray.com — Malware Analysis Spotlight Xbinder Xloader (report)
  • sublime.security — Xloader Deep Dive Link Based Malware Delivery Via Sharepoint Impersonation (report)
  • medium.com — Layers Of Deception Analyzing The Complex Stages Of Xloader 4 3 Malware Evolution 2Dcb550B98D9 (report)
  • zscaler.com — Analysis Xloaders C2 Network Encryption (report)
  • research.checkpoint.com — Time Proven Tricks In A New Environment The Macos Evolution Of Formbook (report)
  • sentinelone.com — Xloaders Latest Trick New Macos Variant Disguised As Signed Officenote App (report)
  • research.checkpoint.com — Xloader Botnet Find Me If You Can (report)
  • twitter.com — 1319463908952969216 (report)
  • zscaler.com — Technical Analysis Xloader Versions 6 And 7 Part 2 (report)
  • cip.gov.ua — Khto Stoyit Za Kiberatakami Na Ukrayinsku Kritichnu Informaciinu Infrastrukturu Statistika 15 22 Bereznya (report)
  • research.checkpoint.com — Top Prevalent Malware With A Thousand Campaigns Migrates To Macos (report)
  • malwarebookreports.com — Cross Platform Java Dropper Snake And Xloader Mac Version (report)
  • any.run — Xloader Formbook Encryption Analysis And Malware Decryption (report)
  • MITRE ATT&CK — S1207 (report)
  • cloud.google.com — Formbook Malware Distribution Campaigns (report)
  • acronis.com — Trojan As A Service From Formbook To Xloader (report)

External references