PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1041 Exfiltration Over C2 Channel |
GroupCURIUM | CURIUM has used IMAP and SMTPS for exfiltration via tools such as IMAPLoader. |
| T1047 Windows Management Instrumentation |
MalwareIMAPLoader | IMAPLoader uses WMI queries to query system information on victim hosts. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
GroupCURIUM | CURIUM has used SMTPS to exfiltrate collected data from victims. |
| T1053.005 Scheduled Task |
MalwareIMAPLoader | IMAPLoader creates scheduled tasks for persistence based on the operating system version of the victim machine. |
| T1071.003 Mail Protocols |
MalwareIMAPLoader | IMAPLoader uses the IMAP email protocol for command and control purposes. |
| T1082 System Information Discovery |
MalwareIMAPLoader | IMAPLoader uses WMI queries to gather information about the victim machine. |
| T1105 Ingress Tool Transfer |
MalwareIMAPLoader | IMAPLoader is a loader used to retrieve follow-on payload encoded in email messages for execution on victim systems. |
| T1106 Native API |
MalwareIMAPLoader | IMAPLoader imports native Windows APIs such as `GetConsoleWindow` and `ShowWindow`. |
| T1124 System Time Discovery |
GroupCURIUM | CURIUM deployed mechanisms to check system time information following strategic website compromise attacks. |
| T1189 Drive-by Compromise |
GroupCURIUM | CURIUM has used strategic website compromise to infect victims with malware such as IMAPLoader. |
| T1543 Create or Modify System Process |
MalwareIMAPLoader | IMAPLoader modifies Windows tasks on the victim machine to reference a retrieved PE file through a path modification. |
| T1564.003 Hidden Window |
MalwareIMAPLoader | IMAPLoader hides the Windows Console window created by its execution by directly importing the `kernel32.dll` and `user32.dll` libraries `GetConsoleWindow` and `ShowWindow` APIs. |
| T1566.001 Spearphishing Attachment |
GroupCURIUM | CURIUM has used phishing with malicious attachments for initial access to victim environments. |
| T1574.014 AppDomainManager |
MalwareIMAPLoader | IMAPLoader is executed via the AppDomainManager injection technique. |
| T1583.001 Domains |
GroupCURIUM | CURIUM created domains to facilitate strategic website compromise and credential capture activities. |
| T1583.003 Virtual Private Server |
GroupCURIUM | CURIUM created virtual private server instances to facilitate use of malicious domains and other items. |
| T1583.004 Server |
GroupCURIUM | CURIUM has created dedicated servers for command and control and exfiltration purposes. |
| T1584.006 Web Services |
GroupCURIUM | CURIUM has compromised legitimate websites to enable strategic website compromise attacks. |
| T1585.002 Email Accounts |
GroupCURIUM | CURIUM has created dedicated email accounts for use with tools such as IMAPLoader. |
| T1598.003 Spearphishing Link |
GroupCURIUM | CURIUM used malicious links to adversary-controlled resources for credential harvesting. |
| T1608.004 Drive-by Target |
GroupCURIUM | CURIUM used strategic website compromise to fingerprint then target victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.