GRIDINSOFT HELP CENTER

FormBook Malware: Credential Theft and Response

What it is

FormBook is spyware for Windows that sneaks onto a PC to steal files and data. It can log what you type, grab passwords and cookies from browsers, and take screenshots, then send everything back to the attacker.

What you may notice

  • Sudden logouts or new MFA prompts you didn’t start

  • Unknown browser extensions or odd redirects

  • Network spikes after opening an email or installer

  • Apps crash or settings change without reason

How it gets in

  • Phishing emails with booby-trapped attachments

  • Fake updates and bundled “free” installers

  • Malvertising and shady download sites

Remove it now - quick steps

  1. Disconnect from the internet and avoid banking or email on the infected device.

  2. Run a full anti-malware scan, quarantine findings, reboot, then scan again.

  3. From a clean device, change passwords and enable MFA.

  4. Review startup items, scheduled tasks, and extensions - remove unknowns.

  5. Move any crypto to new wallets with fresh seed phrases.

Prevent it

  • Install software only from official sources - avoid cracks and repacks.

  • Keep Windows, browsers, and plugins updated.

  • Use reputable EDR/anti-malware plus email/web filtering.

  • Be cautious with attachments - block macros by default and preview links before clicking.

Cleanup must address stolen data

FormBook can expose browser data, credentials, screenshots, and other information available to the infected account. Isolate and scan the device, but assume secrets used during the infection window may be compromised. From a clean device, revoke sessions, rotate passwords, review mailbox rules, and replace saved credentials. Check the original attachment or download so the same lure can be removed from other inboxes. Monitor for follow-on access after cleanup. Treat the incident like spyware exposure and enable MFA after resetting the primary credentials.

Helpful?

Glossary (0-9, A-Z)

Still can’t find an answer?

Send us a ticket and we will get back to you.

Submit a ticket