SYMBOLCOMMON_NAMEaka. SYNONYMS
osx.xloader (Back to overview)

Xloader

aka: Formbook

Xloader is a Rebranding of Formbook malware (mainly a stealer), available for macOS as well.

Formbook has a "magic"-value FBNG (FormBook-NG), while Xloader has a "magic"-value XLNG (XLoader-NG). This "magic"-value XLNG is platform-independent.

Not to be confused with apk.xloader or ios.xloader.

References
2026-04-16 ⋅ YouTube (botconf eu) ⋅ Alexey Bukhteyev, Souhail Hammou
Chasing XLoader: Tracking a Notoriously Complex Malware Family at Scale
Xloader Formbook
2026-03-24 ⋅ Zynap ⋅ Alberto Marín
Defensive Rootkits: Engineering Kernel-Level Malware Analysis from Ring 0
Xloader CloudEyE Lumma Stealer SmokeLoader
2026-01-27 ⋅ Medium mk7912 ⋅ Manoj Kshirsagar
From XLoader to Phantom Stealer: A DHL-Themed multi-stage Infection Chain
Xloader Phantom Stealer
2025-02-13 ⋅ Zscaler ⋅ ThreatLabZ research team, Zscaler
Technical Analysis of Xloader Versions 6 and 7 | Part 2
Xloader
2025-01-27 ⋅ Zscaler ⋅ ThreatLabZ research team, Zscaler
Technical Analysis of Xloader Versions 6 and 7 | Part 1
Xloader
2024-12-11 ⋅ Sublime ⋅ Sublime Security
Xloader deep dive: Link-based malware delivery via SharePoint impersonation
Xloader Formbook
2024-01-24 ⋅ Medium shaddy43 ⋅ Shayan Ahmed Khan
Layers of Deception: Analyzing the Complex Stages of XLoader 4.3 Malware Evolution
Xloader Formbook
2023-08-21 ⋅ SentinelOne ⋅ Dinesh Devadoss, Phil Stokes
XLoader's Latest Trick | New macOS Variant Disguised as Signed OfficeNote App
Xloader
2022-05-31 ⋅ Check Point Research ⋅ Alexey Bukhteyev, Raman Ladutska
XLoader Botnet: Find Me If You Can
Xloader
2022-03-25 ⋅ GOV.UA ⋅ State Service of Special Communication and Information Protection of Ukraine (CIP)
Who is behind the Cyberattacks on Ukraine's Critical Information Infrastructure: Statistics for March 15-22
Xloader Agent Tesla CaddyWiper Cobalt Strike DoubleZero GraphSteel GrimPlant HeaderTip HermeticWiper IsaacWiper MicroBackdoor Pandora RAT
2022-03-07 ⋅ ⋅ LAC WATCH ⋅ Cyber ​​Emergency Center
I CAN'T HEAR YOU NOW! INTERNAL BEHAVIOR OF INFORMATION-STEALING MALWARE AND JSOC DETECTION TRENDS
Xloader Agent Tesla Formbook Loki Password Stealer (PWS)
2022-01-21 ⋅ Zscaler ⋅ Brett Stone-Gross, Javier Vicente
Analysis of Xloader’s C2 Network Encryption
Xloader Formbook
2022-01-06 ⋅ VMRay ⋅ VMRay Labs Team
Malware Analysis Spotlight: XLoader’ Cross-platform Support Utilizing XBinder
Xloader
2021-09-30 ⋅ Blackberry ⋅ The BlackBerry Research & Intelligence Team
Threat Thursday: xLoader Infostealer
Xloader Formbook
2021-09-02 ⋅ MalwareBookReports ⋅ muzi
Cross-Platform Java Dropper: Snake and XLoader (Mac Version)
Xloader 404 Keylogger
2021-07-27 ⋅ Check Point ⋅ Alexey Bukhteyev, Raman Ladutska
Time-proven tricks in a new environment: the macOS evolution of Formbook
Xloader
2021-07-26 ⋅ Malwarebytes ⋅ Thomas Reed
OSX.XLoader hides little except its main purpose: What we learned in the installation process
Xloader
2021-07-26 ⋅ SentinelOne ⋅ Phil Stokes
Detecting XLoader | A macOS ‘Malware-as-a-Service’ Info Stealer and Keylogger
Xloader
2021-07-21 ⋅ Check Point ⋅ Check Point Research
Top prevalent malware with a thousand campaigns migrates to macOS
Xloader
2020-10-23 ⋅ @krabsonsecurity
Tweet: An interesting tidbit: it has a Mach-O bin
Xloader

There is no Yara-Signature yet.