IMAPLoader — Malware Profile
IMAPLoader is a .NET-based loader malware exclusively associated with CURIUM operations since at least 2022. IMAPLoader leverages email protocols for command and control and payload delivery.
MITRE ATT&CK techniques (9)
- T1047 Windows Management Instrumentation
- T1053.005 Scheduled Task
- T1071.003 Mail Protocols
- T1082 System Information Discovery
- T1105 Ingress Tool Transfer
- T1106 Native API
- T1543 Create or Modify System Process
- T1564.003 Hidden Window
- T1574.014 AppDomainManager