Skip to content

Colibri

Colibri is a Windows malware loader offered as a malware-as-a-service tool and observed since 2021 in underground criminal markets and active delivery chains.

Profile source: Mallory opens in a new tab

Colibri

Family profile

Colibri is a Windows malware loader offered as a malware-as-a-service tool and observed since 2021 in underground criminal markets and active delivery chains. Its primary role is to download and execute additional payloads on compromised hosts, including information stealers such as Vidar. Colibri has been associated with campaigns using malicious Microsoft Word documents with remote template injection, and it has also appeared among malware families distributed through broader loader ecosystems such as PrivateLoader. Reported delivery themes include trojanized software and document-based infection chains.

Technically, Colibri is designed to hinder analysis and detection. Reported samples omit a conventional Import Address Table, encrypt strings, use self-modifying code, and dynamically resolve WinAPI functions through hashing and arithmetic operations rather than normal imports. It also uses basic anti-analysis and execution control measures such as mutex creation to prevent multiple instances and delayed execution before network activity.

Colibri communicates with command-and-control infrastructure over encrypted channels and retrieves additional content for execution, with analysis indicating downloaded data may be encrypted and decoded on the host before use. Its persistence tradecraft on Windows includes scheduled-task abuse. A documented technique copies the malware into a user-accessible WindowsApps location under a name that collides with a legitimate PowerShell cmdlet, then uses a scheduled task to invoke PowerShell in a way that causes the malicious executable to run, providing persistence across reboots while reducing visibility. This behavior has been highlighted as a notable example of path interception and scheduled-task-based persistence on Windows 10 and later systems.

Colibri targets Windows systems, including Windows Server, and is best characterized as a stealth-focused loader used to establish footholds and deliver follow-on malware for financially motivated intrusion activity.

Capabilities

  • Defense Evasion
  • Persistence
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 25, 2026
Last activity
Sep 25, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • RU1

Leading providers

  • JSC IOT1

Infrastructure traits

  • Hosting 1

MITRE ATT&CK

Colibri in ATT&CK

16 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.