Skip to content

Expiro

Expiro is a long-running Windows file-infector malware family that also functions as an information stealer and bot-capable backdoor.

Profile source: Mallory opens in a new tab

Expiro

Family profile

Expiro is a long-running Windows file-infector malware family that also functions as an information stealer and bot-capable backdoor. It infects 32-bit and 64-bit executable files by appending or inserting malicious code into host binaries, including cross-architecture infection in some variants, and can propagate by infecting executables on local, removable, and network drives. Expiro is notable for preserving host execution after its own payload runs, while using polymorphic infection logic and modifications to relocation data that complicate analysis, disinfection, and file repair. Some variants encrypt or alter relocation structures, making conventional repair routines unreliable and increasing the risk of file corruption during cleanup.

Beyond file infection, Expiro steals credentials and other sensitive data from browsers and applications, including email and FTP clients, and can capture web form submissions such as account, banking, and payment-card information. It has also been observed installing malicious browser extensions, lowering browser security settings, redirecting users, and harvesting confidential information entered into web sessions. Additional functionality includes theft of certificates and private keys, execution of shell commands, downloading and launching plugins, proxying, port forwarding, and TCP flood denial-of-service activity.

Expiro employs multiple defense-evasion measures, including anti-debugging and anti-analysis techniques, polymorphism, tampering with signed executables, disabling security services, and terminating selected security-related processes. Its ability to reinfect systems from any remaining infected executable makes eradication difficult in both home and enterprise environments. The malware has been active for more than a decade and remains one of the better-known Windows file infectors due to its combination of parasitic infection, credential theft, browser manipulation, and post-compromise bot functionality.

Capabilities

  • Credential Theft
  • Ddos
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Reconnaissance
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 19, 2026
Last activity
Sep 19, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • DE1

Leading providers

  • Leaseweb Deutschland GmbH1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

MITRE ATT&CK

Expiro in ATT&CK

28 distinct techniques

Reporting

Research mentioning Expiro

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.