Malware.View on attack.mitre.org
IMAPLoader is a .NET-based loader malware exclusively associated with CURIUM operations since at least 2022. IMAPLoader leverages email protocols for command and control and payload delivery.
| Technique | Procedure example |
|---|---|
| T1047 Windows Management Instrumentation |
IMAPLoader uses WMI queries to query system information on victim hosts. |
| T1053.005 Scheduled Task |
IMAPLoader creates scheduled tasks for persistence based on the operating system version of the victim machine. |
| T1071.003 Mail Protocols |
IMAPLoader uses the IMAP email protocol for command and control purposes. |
| T1082 System Information Discovery |
IMAPLoader uses WMI queries to gather information about the victim machine. |
| T1105 Ingress Tool Transfer |
IMAPLoader is a loader used to retrieve follow-on payload encoded in email messages for execution on victim systems. |
| T1106 Native API |
IMAPLoader imports native Windows APIs such as `GetConsoleWindow` and `ShowWindow`. |
| T1543 Create or Modify System Process |
IMAPLoader modifies Windows tasks on the victim machine to reference a retrieved PE file through a path modification. |
| T1564.003 Hidden Window |
IMAPLoader hides the Windows Console window created by its execution by directly importing the `kernel32.dll` and `user32.dll` libraries `GetConsoleWindow` and `ShowWindow` APIs. |
| T1574.014 AppDomainManager |
IMAPLoader is executed via the AppDomainManager injection technique. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.