Nart Villeneuve, Randi Eitzman, Sandor Nemes & Tyler Dean, Google Cloud. (2017, October 5). Significant FormBook Distribution Campaigns Impacting the U.S. and South Korea. Retrieved March 11, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1055.012 Process Hollowing |
MalwareXLoader | XLoader uses process hollowing by injecting itself into the `explorer.exe` process and other files ithin the Windows `SysWOW64` directory. |
| T1056.001 Keylogging |
MalwareXLoader | XLoader can capture keystrokes from the victim machine. |
| T1059.010 AutoHotKey & AutoIT |
MalwareXLoader | XLoader can use an AutoIT script to decrypt a payload file, load it into victim memory, then execute it on the victim machine. |
| T1071.001 Web Protocols |
MalwareXLoader | XLoader uses HTTP and HTTPS for command and control communication. |
| T1113 Screen Capture |
MalwareXLoader | XLoader can capture screenshots on compromised hosts. |
| T1115 Clipboard Data |
MalwareXLoader | XLoader can collect data stored in the victim's clipboard. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareXLoader | XLoader uses XOR and RC4 algorithms to decrypt payloads and functions. XLoader can be distributed as a self-extracting RAR archive that launches an AutoIT loader. |
| T1185 Browser Session Hijacking |
MalwareXLoader | XLoader can conduct form grabbing, steal cookies, and extract data from HTTP sessions. |
| T1497.001 System Checks |
MalwareXLoader | XLoader performs timing checks using the Read-Time Stamp Counter (RDTSC) instruction on the victim CPU. |
| T1529 System Shutdown/Reboot |
MalwareXLoader | XLoader can initiate a system reboot or shutdown. |
| T1539 Steal Web Session Cookie |
MalwareXLoader | XLoader can capture web session cookies and session information from victim browsers. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareXLoader | XLoader establishes persistence by copying its executable in a subdirectory of `%APPDATA%` or `%PROGRAMFILES%`, and then modifies Windows Registry Run keys or policies keys to execute the executable on system start. |
| T1555 Credentials from Password Stores |
MalwareXLoader | XLoader can collect credentials stored in email clients. |
| T1555.003 Credentials from Web Browsers |
MalwareXLoader | XLoader can gather credentials from several web browsers. |
| T1566.001 Spearphishing Attachment |
MalwareXLoader | XLoader has been delivered as a phishing attachment, including PDFs with embedded links, Word and Excel files, and various archive files (ZIP, RAR, ACE, and ISOs) containing EXE payloads. |
| T1622 Debugger Evasion |
MalwareXLoader | XLoader uses anti-debugging mechanisms such as calling `NtQueryInformationProcess` with `InfoClass=7`, referencing `ProcessDebugPort`, to determine if it is being analyzed. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.