IMAPLoader is a Windows malware family that uses the IMAP email protocol for command and control. Reported behavior includes hiding the Windows console window during execution by importing and using GetConsoleWindow from kernel32.dll and ShowWindow from user32.dll, querying victim system information via WMI, and creating scheduled tasks for persistence based on the victim host’s operating system version. The malware has been associated with the Iranian threat actor CURIUM, which has used strategic website compromise and drive-by compromise to infect victims with IMAPLoader, created dedicated email accounts to support its use, and used IMAP and SMTPS for exfiltration via tools such as IMAPLoader. The content also notes that Tortoiseshell has delivered IMAPLoader through malicious Excel documents using AppDomainManager injection. High-confidence capabilities directly mentioned in the source include hidden execution, system discovery through WMI, scheduled-task persistence, and IMAP-based C2.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CURIUM has created dedicated email accounts for use with tools such as IMAPLoader.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
APT1 has created email accounts for later use in social engineering, phishing, and when registering domains. APT42 has created email accounts to use in spearphishing operations. Contagious Interview has created fake email accounts to correspond with social media accounts, fake LinkedIn personas, code repository accounts, and job announcements on development job board services.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
Cannon exfiltrates collected data over email via SMTP/S and POP3/S C2 channels... CURIUM has used IMAP and SMTPS for exfiltration via tools such as IMAPLoader... Kevin can send data from the victim host through a DNS C2 channel... NightClub can use SMTP and DNS for file exfiltration and C2.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader delivered via malicious Excel documents using AppDomainManager injection (as referenced in prior Iranian-linked campaigns).
A malware tool used by CURIUM in strategic website compromise operations and for exfiltration over IMAP and SMTPS channels.
Tool/malware used with dedicated email accounts by CURIUM.
Loader that creates scheduled tasks for persistence depending on OS version.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.