Formbook
Also known as: win.xloader
FormBook contains a unique crypter RunPE that has unique behavioral patterns subject to detection. It was initially called "Babushka Crypter" by Insidemalware.
Linked Threat Actors
Last 7 days
| Date | C2 Hosts |
|---|---|
| Mar 3, 2026 | 1 |
Further Reading
In this article, we briefly detail what IPFS is and how it works at the user level, before providing up to date statistics about the current usage of IPFS by cybercriminals, especially for hosting ...
Formbook is an infostealer that has been advertised for sale in public hacking forums since February 2016 by a user with the handle ‘ng-Coder' but only came to public attention after it was extensi...
This blog post provides a detailed analysis of Xloader C2 communications and its hosting network infrastructure.
Analysis of the new variant of Xloader information stealer malware that identifies itself as version 4.3, released on January 2023.
Costruiamo un digitale sicuro, insieme. Sicurezza, Resilienza, Innovazione Tinexta Cyber è una delle principali realtà italiane nel campo della cybersecurity e della system integration, parte del G...