Malware
Expiro
aka Xpiro
Expiro malware has been around for more than a decade, and the malware authors sill continue their work and update it with more features.
Expiro, also known as Xpiro, is a Windows malware family.
Background
Expiro has existed for over ten years, and its developers keep maintaining and expanding it with additional functionality. McAfee documented a revised infection routine in samples discovered in 2017. The malware infects executables on both 32- and 64-bit versions of Windows, and it can install browser extensions, alter security settings and behavior on the host, and harvest information such as account credentials. A separate EPO file infector source code dubbed m0yv surfaced in 2022 and is sometimes incorrectly flagged as Expiro by certain antivirus products.
Source: Malpedia (Fraunhofer FKIE).