Last seven days
- First activity
- Sep 19, 2026
- Last activity
- Sep 19, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
Expiro is a long-running Windows file-infector malware family that also functions as an information stealer and bot-capable backdoor.
Profile source: Mallory opens in a new tabExpiro
Expiro is a long-running Windows file-infector malware family that also functions as an information stealer and bot-capable backdoor. It infects 32-bit and 64-bit executable files by appending or inserting malicious code into host binaries, including cross-architecture infection in some variants, and can propagate by infecting executables on local, removable, and network drives. Expiro is notable for preserving host execution after its own payload runs, while using polymorphic infection logic and modifications to relocation data that complicate analysis, disinfection, and file repair. Some variants encrypt or alter relocation structures, making conventional repair routines unreliable and increasing the risk of file corruption during cleanup.
Beyond file infection, Expiro steals credentials and other sensitive data from browsers and applications, including email and FTP clients, and can capture web form submissions such as account, banking, and payment-card information. It has also been observed installing malicious browser extensions, lowering browser security settings, redirecting users, and harvesting confidential information entered into web sessions. Additional functionality includes theft of certificates and private keys, execution of shell commands, downloading and launching plugins, proxying, port forwarding, and TCP flood denial-of-service activity.
Expiro employs multiple defense-evasion measures, including anti-debugging and anti-analysis techniques, polymorphism, tampering with signed executables, disabling security services, and terminating selected security-related processes. Its ability to reinfect systems from any remaining infected executable makes eradication difficult in both home and enterprise environments. The malware has been active for more than a decade and remains one of the better-known Windows file infectors due to its combination of parasitic infection, credential theft, browser manipulation, and post-compromise bot functionality.
C2 tracking
Derp observations, rolling seven-day window
Samples
MITRE ATT&CK
Reporting
Researchers reported that Win64/Expiro.A can infect both 32-bit and 64-bit Windows executables, allowing the malware to spread widely across local disks, removable media, and network drives. The file infector can repeatedly re-establish itself from any remaining tainted executable, complicating cleanup and increasing the risk of enterprise-wide reinfection. Beyond file infection, the malware steals credentials and sensitive data from Internet Explorer, Microsoft Outlook, FileZilla, and Windows certificate stores, while also manipulating browsers by installing malicious extensions for Google Chrome and Mozilla Firefox. It can intercept web form data tied to banking and payment activity, disable protections including Windows Defender and Security Center, terminate security-related processes, and provide botnet functions such as remote command execution, plugin loading, proxying, port forwarding, and TCP flood attacks.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.