Last seven days
- First activity
- Sep 25, 2026
- Last activity
- Sep 25, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
Colibri is a Windows malware loader offered as a malware-as-a-service tool and observed since 2021 in underground criminal markets and active delivery chains.
Profile source: Mallory opens in a new tabColibri
Colibri is a Windows malware loader offered as a malware-as-a-service tool and observed since 2021 in underground criminal markets and active delivery chains. Its primary role is to download and execute additional payloads on compromised hosts, including information stealers such as Vidar. Colibri has been associated with campaigns using malicious Microsoft Word documents with remote template injection, and it has also appeared among malware families distributed through broader loader ecosystems such as PrivateLoader. Reported delivery themes include trojanized software and document-based infection chains.
Technically, Colibri is designed to hinder analysis and detection. Reported samples omit a conventional Import Address Table, encrypt strings, use self-modifying code, and dynamically resolve WinAPI functions through hashing and arithmetic operations rather than normal imports. It also uses basic anti-analysis and execution control measures such as mutex creation to prevent multiple instances and delayed execution before network activity.
Colibri communicates with command-and-control infrastructure over encrypted channels and retrieves additional content for execution, with analysis indicating downloaded data may be encrypted and decoded on the host before use. Its persistence tradecraft on Windows includes scheduled-task abuse. A documented technique copies the malware into a user-accessible WindowsApps location under a name that collides with a legitimate PowerShell cmdlet, then uses a scheduled task to invoke PowerShell in a way that causes the malicious executable to run, providing persistence across reboots while reducing visibility. This behavior has been highlighted as a notable example of path interception and scheduled-task-based persistence on Windows 10 and later systems.
Colibri targets Windows systems, including Windows Server, and is best characterized as a stealth-focused loader used to establish footholds and deliver follow-on malware for financially motivated intrusion activity.
C2 tracking
Derp observations, rolling seven-day window
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.