Netskope Threat Labs

Expiro

ATP Sandbox Adv. HeuristicsAV

Expiro is a file infector that spreads by injecting its code into executable files, so every infected program carries the malware to new systems. It steals credentials and sensitive data, disables security products, and resists analysis through anti emulation and server side logic that varies by victim. Its dual nature as both an infector and an information stealer makes it unusually dangerous, because cleaning infected files requires specialized remediation rather than simple deletion.

First seen
May 2022
Last seen
October 2026
Alert Name
Win32.Expiro.DE
Win32.Expiro.Gen.2
Win32.Expiro.Gen.3
Win32.Expiro.Gen.4
Win32.Expiro.Gen.6
Win32.Expiro.Gen.7
Win32.Virus.Expiro
Win64.Expiro.Gen.2
Win64.Expiro.Gen.4
Win64.Expiro.Gen.6