Xloader
Also known as: Formbook
Xloader is a Rebranding of Formbook malware (mainly a stealer), available for macOS as well.
Formbook has a "magic"-value FBNG (FormBook-NG), while Xloader has a "magic"-value XLNG (XLoader-NG). This "magic"-value XLNG is platform-independent.
Not to be confused with apk.xloader or ios.xloader.
C2 Infrastructure
Last 7 days
| Date | C2 Hosts |
|---|---|
| Apr 10, 2026 | 1 |
Further Reading
We analyze the XLoader malware for macOS, describing its behavior, listing Indicators of Compromise and showing how it can be detected on a Mac.
Notorious botnet and infostealer XLoader makes a return to macOS with a new dropper and malware payload.
This blog post provides a detailed analysis of Xloader C2 communications and its hosting network infrastructure.
Technical analysis of Xloader versions 6 and 7 Part 1 | Labyrinthian obfuscation and encryption techniques to evade detection and hinder analysis
Technical analysis of Xloader versions 6 and 7 Part 2 | Multi-layered RC4 encryption, dynamic key generation, and obfuscated C2 lists for communication