Skip to content

Malware

Expiro

aka Xpiro

Expiro malware has been around for more than a decade, and the malware authors sill continue their work and update it with more features.

Expiro, also known as Xpiro, is a Windows malware family.

Background

Expiro has existed for over ten years, and its developers keep maintaining and expanding it with additional functionality. McAfee documented a revised infection routine in samples discovered in 2017. The malware infects executables on both 32- and 64-bit versions of Windows, and it can install browser extensions, alter security settings and behavior on the host, and harvest information such as account credentials. A separate EPO file infector source code dubbed m0yv surfaced in 2022 and is sometimes incorrectly flagged as Expiro by certain antivirus products.


Source: Malpedia (Fraunhofer FKIE).