XLoader

S1207

Malware.View on attack.mitre.org

About this malware

XLoader is an infostealer malware in use since at least 2016. Previously known and sometimes still referred to as Formbook, XLoader is a Malware as a Service (MaaS) known for stealing data from web browsers, email clients and File Transfer Protocol (FTP) applications.

Techniques used28

Procedure examples28

TechniqueProcedure example
T1027.002
Software Packing

XLoader uses various packers, including CyaX, to obfuscate malicious executables.

T1027.013
Encrypted/Encoded File

XLoader features encrypted functions using the RC4 algorithm and bytecode operations.

T1033
System Owner/User Discovery

XLoader can identify the username from a victim machine.

T1053.005
Scheduled Task

XLoader can create scheduled tasks for persistence.

T1055.004
Asynchronous Procedure Call

XLoader injects code into the APC queue using `NtQueueApcThread` API.

T1055.012
Process Hollowing

XLoader uses process hollowing by injecting itself into the `explorer.exe` process and other files ithin the Windows `SysWOW64` directory.

T1056.001
Keylogging

XLoader can capture keystrokes from the victim machine.

T1059.010
AutoHotKey & AutoIT

XLoader can use an AutoIT script to decrypt a payload file, load it into victim memory, then execute it on the victim machine.

T1070.004
File Deletion

XLoader can delete malicious executables from compromised machines.

T1071.001
Web Protocols

XLoader uses HTTP and HTTPS for command and control communication.

T1082
System Information Discovery

XLoader can collect system information and supported language information from the victim machine.

T1106
Native API

XLoader uses the native Windows API for functionality, including defense evasion.

T1113
Screen Capture

XLoader can capture screenshots on compromised hosts.

T1115
Clipboard Data

XLoader can collect data stored in the victim's clipboard.

T1140
Deobfuscate/Decode Files or Information

XLoader uses XOR and RC4 algorithms to decrypt payloads and functions. XLoader can be distributed as a self-extracting RAR archive that launches an AutoIT loader.

View all 28 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References5

  1. ANY.RUN XLoader 2023 Open source
    ANY.RUN. (2023, February 28). XLoader/FormBook: Encryption Analysis and Malware Decryption . Retrieved March 11, 2025.
  2. Acronis XLoader 2021 Open source
    Acronis. (2021, November 26). Trojan-as-a-service: From Formbook to XLoader. Retrieved March 11, 2025.
  3. CheckPoint XLoader 2022 Open source
    Alexey Bukhteyev & Raman Ladutska, Check Point Research. (2022, May 31). XLoader Botnet: Find Me If You Can. Retrieved March 11, 2025.
  4. Google XLoader 2017 Open source
    Nart Villeneuve, Randi Eitzman, Sandor Nemes & Tyler Dean, Google Cloud. (2017, October 5). Significant FormBook Distribution Campaigns Impacting the U.S. and South Korea. Retrieved March 11, 2025.
  5. Zscaler XLoader 2025 Open source
    Zscaler Threatlabz. (2025, January 27). Technical Analysis of Xloader Versions 6 and 7 | Part 1. Retrieved March 11, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.