Formbook indicators tracked by ThreatFox

Report date September 11, 2026

FormBook is malware that steals saved passwords from browsers and email programs. It can also record what someone types on an infected Windows device.

Background

Mandiant's FormBook investigation documented malicious email attachments that installed the malware. Microsoft's analysis describes password theft and keylogging. These explain the malware family; they are not an analysis of each file listed below.

What to do

If your antivirus reports FormBook, open its detection history to see whether the threat was blocked, quarantined or still needs action. If you use Microsoft Defender on Windows, open Windows Security > Virus & threat protection > Protection history. If the status is Threat found - action needed, follow Defender's recommended action. Threat blocked means Defender reports it removed that threat. Keep a quarantined file quarantined; do not choose Allow on device.

If FormBook ran, stop using that device for passwords or banking and contact IT on a work device. On a personal Windows device, run a full antivirus scan and follow its removal instructions. From a clean device, change passwords stored or entered on the infected device. Removing malware does not undo stolen credentials. Follow the affected service's account recovery steps.

Feed records

This report links to ThreatFox's indicator search for Formbook. The background above was checked on 2026-09-08; the feed records have their own observation dates.