Netskope Threat Labs

XLoader

ATP Sandbox Adv. HeuristicsAVNetskope IPS

XLoader is a cross platform malware as a service family, descended from FormBook, that steals credentials, browser data, and other sensitive information from infected systems. Its operators sell subscriptions on underground forums, and ports of the family extended its reach to macOS and Android alongside its original Windows base. Its campaigns arrive through phishing and fake software downloads, and its longevity reflects steady development and a reliable buyer market.

First seen
March 2022
Last seen
October 2026
FormBookFormbookXloader

28 techniques across 11 tactics.

TA0042 Resource Development

TA0001 Initial Access

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0006 Credential Access

  • T1539Steal Web Session Cookie
  • T1555Credentials from Password Stores

TA0007 Discovery

  • T1033System Owner/User Discovery
  • T1082System Information Discovery

TA0009 Collection

TA0011 Command and Control

TA0040 Impact

  • T1529System Shutdown/Reboot

TA0112 Defense Impairment

  • T1685Disable or Modify Tools
Alert Name
Adware.MAC.OSX.XLoader.A
AIT:Trojan.Formbook.345
AIT:Trojan.Formbook.380
AIT:Trojan.Formbook.384
Binary.Backdoor.FormBook
ByteCode-MSIL.Backdoor.FormBook
ByteCode-MSIL.Downloader.FormBook
ByteCode-MSIL.Spyware.FormBook
ByteCode-MSIL.Trojan.FormBook
ByteCode-MSIL.Trojan.XLoader