IMAPLoader is a Windows malware implant associated with the Iranian-aligned threat actor CURIUM, also known as Imperial Kitten, Tortoiseshell, TA456, Yellow Liderc, and Crimson Sandstorm. It uses the IMAP email protocol for command-and-control communications, supported by operator-controlled email accounts, and has also been used with IMAP and SMTPS to exfiltrate data. IMAPLoader queries victim-host system information through Windows Management Instrumentation, establishes persistence through scheduled tasks selected according to the Windows version, and hides its console window using Windows API calls to reduce user visibility. CURIUM has distributed IMAPLoader through strategic website compromise and drive-by infection, while Tortoiseshell has delivered it in malicious Excel documents using AppDomainManager injection. The malware has been used in espionage activity targeting organizations in transportation, logistics, technology, defense, telecommunications, maritime, energy, consulting, and professional-services sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Imperial Kitten uses several malware families, including custom implants; IMAPLoader and StandardKeyboard, which both use email for command and control (C2) communication.
CURIUM has created dedicated email accounts for use with tools such as IMAPLoader.
CURIUM has used strategic website compromise to infect victims with malware such as IMAPLoader. CURIUM has created dedicated email accounts for use with tools such as IMAPLoader. CURIUM has used IMAP and SMTPS for exfiltration via tools such as IMAPLoader.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
APT1 has created email accounts for later use in social engineering, phishing, and when registering domains. APT42 has created email accounts to use in spearphishing operations. Contagious Interview has created fake email accounts to correspond with social media accounts, fake LinkedIn personas, code repository accounts, and job announcements on development job board services.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
Cannon exfiltrates collected data over email via SMTP/S and POP3/S C2 channels... CURIUM has used IMAP and SMTPS for exfiltration via tools such as IMAPLoader... Kevin can send data from the victim host through a DNS C2 channel... NightClub can use SMTP and DNS for file exfiltration and C2.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader malware that hides its console window using GetConsoleWindow and ShowWindow APIs.
Loader delivered via malicious Excel documents using AppDomainManager injection (as referenced in prior Iranian-linked campaigns).
A malware tool used by CURIUM in strategic website compromise operations and for exfiltration over IMAP and SMTPS channels.
Tool/malware used with dedicated email accounts by CURIUM.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.