Formbook
Aliases: win.xloader
- First seen
- 2016-07-01 00:00:00
- Malware type
- credential-stealer, keylogger, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-22 04:24:40
- Profile updated
- 2026-07-07 15:45:42
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Context
FormBook contains a unique crypter RunPE that has unique behavioral patterns subject to detection. It was initially called "Babushka Crypter" by Insidemalware.
Used by threat actors
- TA2536 (threat-actor)
Exploited vulnerabilities
- CVE-2017-11882 (vulnerability)
Reports & references
- slideshare.net — Cb19 Cyber Threat Landscape In Japan Revealing Threat In The Shadow By Chi En Shen Ashley Oleg Bondarenko (report)
- Cisco Talos — Sweed Agent Tesla (report)
- ESET — Eset Threat Report Q22020 (report)
- blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
- ptsecurity.com — Steganoamor Campaign Ta558 Mass Attacking Companies And Public Institutions All Around The World (report)
- threatresearch.ext.hp.com — Javascript Malware Dispensing Rats Into The Wild (report)
- intrinsec.com — Intrinsec 2025 Threat Report Trouble In The Air (report)
- marcoramilli.com — C2 Traffic Patterns Personal Notes (report)
- lac.co.jp — 20220307 002893 (report)
- blogs.blackberry.com — Threat Thursday Xloader Infostealer (report)
- sublime.security — Xloader Deep Dive Link Based Malware Delivery Via Sharepoint Impersonation (report)
- medium.com — Layers Of Deception Analyzing The Complex Stages Of Xloader 4 3 Malware Evolution 2Dcb550B98D9 (report)
- zscaler.com — Analysis Xloaders C2 Network Encryption (report)
- proofpoint.com — New Whiteshadow Downloader Uses Microsoft Sql Retrieve Malware (report)
- ciphertechsolutions.com — Roboski Global Recovery Automation (report)
- malwarebytes.com — 20221121 Threat Intel Report Final (report)
- CERT-UA — 955924 (report)
- securityintelligence.com — Roboski Global Recovery Automation (report)
- blog.netlab.360.com — Purecrypter (report)
- securityintelligence.com — Spam Trends Campaigns Senior Superlatives 2023 (report)
- logpoint.com — Logpoint Etpr A Comprehensive Overview On Stealer Malware Families 1 (report)
- research.loginsoft.com — From Innocence To Malice The Onenote Malware Campaign Uncovered (report)
- logpoint.com — Logpoint Etpr A Comprehensive Overview On Stealer Malware Families (report)
- threatresearch.ext.hp.com — Hp Bromium Threat Insights Report Q4 2020 (report)
- news.sophos.com — Raticate (report)