Threat Profile
| Threat Name | Formbook |
|---|---|
| Aliases | win.xloader, XLoader (later variant) |
| Classification | Information Stealer / Keylogger |
| Platform | Windows (all versions from XP through 11) |
| File Type | Windows PE Executable |
| First Observed | Early 2016 |
| Distribution Model | Malware-as-a-Service (MaaS) |
| Crypter/Packer | Custom "Babushka Crypter" with unique RunPE behavior |
| Target Data | Credentials, browser data, FTP clients, email, keystrokes, screenshots |
| Persistence Method | Registry Run keys, scheduled tasks, startup folder entries |
| Detection Rate | High across major antivirus engines (often 40+ detections) |
| Threat Level | High — immediate financial and identity theft risk |
How It Spreads
Formbook reaches victims almost exclusively through email campaigns. The operators behind each rental deployment craft phishing messages tailored to their targets—we've seen invoices, shipping notices, job applications, tax documents, and COVID-related lures. The initial file is rarely the malware itself; instead, you'll receive an attachment designed to trick you into executing the payload. Because Formbook is rented out to many different criminal groups, distribution methods vary week to week. What doesn't change is the reliance on social engineering to get you to open something you shouldn't. The operators know that antivirus software watches for known malware signatures, so they constantly rotate the delivery mechanism to stay ahead of detection. Common distribution vectors include: - **Malicious email attachments** — typically archive files (ZIP, RAR, 7Z) containing executables disguised with PDF or DOC icons - **Office documents with macros** — Word or Excel files that prompt you to "Enable Content" or "Enable Editing," which executes hidden code - **Weaponized PDF files** — exploit documents that launch the payload when opened in vulnerable PDF readers - **JavaScript droppers** — .JS or .JSE files that download and execute Formbook when double-clicked - **Trojanized software installers** — legitimate-looking programs bundled with the malware, often distributed via fake download sites or torrent repositories - **Archive bombs** — nested ZIP files designed to evade automated email scanners before delivering the payloadWhat It Does On Your Machine
Once executed, Formbook unpacks itself using a custom crypter nicknamed "Babushka" by malware researchers. This crypter employs a technique called process hollowing or RunPE: it launches a legitimate Windows process (often explorer.exe or a system utility), suspends it, replaces its memory with malicious code, and resumes execution. To your Task Manager, everything looks normal—no suspicious filenames, no obvious red flags. Formbook then establishes persistence so it survives reboots. It typically writes itself to hidden folders in your user profile or AppData directories, then creates registry entries or scheduled tasks to ensure it runs every time Windows starts. The malware operates almost entirely in memory to avoid leaving obvious traces on disk, which makes traditional file-based scanning less effective. The primary function is credential theft. Formbook hooks into your web browsers, email clients, and FTP programs to intercept login credentials as you type them. It captures HTTP POST data before encryption occurs, meaning even HTTPS-protected sites offer no defense once your machine is compromised. It also takes periodic screenshots and logs every keystroke across all applications. All this stolen data gets encrypted and transmitted to a command-and-control server, typically using HTTP POST requests to hacked WordPress sites or compromised web servers.Manual Removal — Step by Step
Disconnect from the internet immediately
Unplug your Ethernet cable or disable WiFi. This stops Formbook from transmitting any additional stolen data and prevents the operators from issuing remote commands to your infected machine.
Boot into Safe Mode with Networking
Restart your computer. As it boots, press F8 repeatedly (or Shift+F8 on newer systems) to access Advanced Boot Options. Select "Safe Mode with Networking." This loads Windows with minimal drivers and prevents most malware from auto-starting, including Formbook's persistence mechanisms.
Run a full scan with updated antivirus software
Open your existing antivirus program and update its definitions before scanning. If you don't have antivirus installed, download Malwarebytes or HitmanPro from a clean computer and transfer via USB drive. Run a complete system scan—this will take 30 minutes to several hours depending on your drive size.
Manually check startup programs and scheduled tasks
Press Win+R, type msconfig, and hit Enter. Go to the Startup tab (or open Task Manager > Startup tab on Windows 8/10/11). Look for unfamiliar entries with random names or paths pointing to AppData folders. Disable anything suspicious. Then open Task Scheduler (search for it in Start menu) and review scheduled tasks for recently-added entries with gibberish names.
Inspect registry Run keys
Press Win+R, type regedit, and navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. Look for entries you don't recognize. Right-click and delete any suspicious values—but be cautious, as legitimate programs also use these keys.
Delete temporary and AppData folders manually
Navigate to C:\Users\[YourUsername]\AppData\Local\Temp and delete all contents. Then check AppData\Roaming for recently-created folders with random names (usually 8-10 characters). Formbook often hides here. Delete any folders you don't recognize, but note that some legitimate programs also store data in AppData.
Clear browser data and check for extensions
Formbook can inject malicious browser extensions. Open each browser (Chrome, Firefox, Edge), go to Extensions or Add-ons, and remove anything you didn't intentionally install. Then clear your browsing history, cache, and saved passwords entirely—assume all stored credentials have been compromised.
Run a second-opinion scanner
Download and run a different scanning tool (if you used Malwarebytes earlier, now try HitmanPro or Microsoft Safety Scanner). Different engines detect different signatures, and Formbook's crypter can sometimes evade a single product. Scan again and remove any additional threats found.
Change all passwords from a clean device
This is critical: do not change passwords from the infected computer, even after cleaning. Use your phone, tablet, or a different computer. Change passwords for email, banking, shopping sites, social media—everything. Enable two-factor authentication wherever possible.
Monitor financial accounts and consider a credit freeze
Review your bank and credit card statements for unauthorized transactions. Set up fraud alerts with your bank. If you entered Social Security numbers, tax information, or other sensitive data during the infection period, consider placing a credit freeze with the three major bureaus (Equifax, Experian, TransUnion).
Prevention
- Never enable macros in unsolicited Office documents. If a Word or Excel file asks you to "Enable Content" or "Enable Editing" and you weren't expecting it, delete it immediately. Legitimate businesses rarely send macro-enabled documents to strangers.
- Scrutinize email attachments before opening. Look at the sender address carefully—not just the display name. Hover over links to see where they really point. If you receive an unexpected invoice, shipping notice, or resume, contact the supposed sender through a separate channel to verify authenticity.
- Avoid opening archive files from unknown sources. ZIP and RAR attachments are a favorite Formbook delivery method. If you must open one, scan it with antivirus first and examine the contents before executing anything inside.
- Keep Windows and all software updated. Many Formbook campaigns exploit known vulnerabilities in PDF readers, Office, or Windows components. Enable automatic updates for Windows, Adobe Reader, Java, browsers, and any other frequently-used software.
- Use a reputable antivirus with real-time protection. Free options like Windows Defender are acceptable if kept updated, but paid solutions often include behavior-based detection that catches Formbook's process injection techniques before they succeed.
- Disable Windows Script Host if you don't need it. Many Formbook droppers arrive as .JS or .VBS files. Most home users never legitimately run script files. You can disable WSH through Group Policy or registry edits, eliminating an entire attack vector.
- Implement email filtering for executable attachments. If you run a small business, configure your email server or service to block .exe, .scr, .js, .vbs, .jar, and other executable file types, even inside archives. Legitimate vendors can send installers via download links instead.
- Back up your data regularly to an offline or cloud location. While Formbook itself isn't ransomware, it's often a precursor to it. Regular backups ensure you can recover if a secondary infection encrypts your files.