ATT&CKSoftwareIMAPLoader

IMAPLoader

S1152

Malware.View on attack.mitre.org

About this malware

IMAPLoader is a .NET-based loader malware exclusively associated with CURIUM operations since at least 2022. IMAPLoader leverages email protocols for command and control and payload delivery.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1047
Windows Management Instrumentation

IMAPLoader uses WMI queries to query system information on victim hosts.

T1053.005
Scheduled Task

IMAPLoader creates scheduled tasks for persistence based on the operating system version of the victim machine.

T1071.003
Mail Protocols

IMAPLoader uses the IMAP email protocol for command and control purposes.

T1082
System Information Discovery

IMAPLoader uses WMI queries to gather information about the victim machine.

T1105
Ingress Tool Transfer

IMAPLoader is a loader used to retrieve follow-on payload encoded in email messages for execution on victim systems.

T1106
Native API

IMAPLoader imports native Windows APIs such as `GetConsoleWindow` and `ShowWindow`.

T1543
Create or Modify System Process

IMAPLoader modifies Windows tasks on the victim machine to reference a retrieved PE file through a path modification.

T1564.003
Hidden Window

IMAPLoader hides the Windows Console window created by its execution by directly importing the `kernel32.dll` and `user32.dll` libraries `GetConsoleWindow` and `ShowWindow` APIs.

T1574.014
AppDomainManager

IMAPLoader is executed via the AppDomainManager injection technique.

Groups that use it1

Campaigns0

None recorded.

References1

  1. PWC Yellow Liderc 2023 Open source
    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.