IMAPLoader is a Windows malware family associated with the Iranian threat actor CURIUM, also known as Tortoiseshell activity clusters in some reporting. It is notable for using the IMAP email protocol as a command-and-control channel, allowing operator communications to blend with legitimate email traffic. The malware has also been linked to exfiltration workflows using email protocols, including IMAP and SMTPS, in operations attributed to CURIUM.
Observed tradecraft shows IMAPLoader performing host discovery through WMI queries to collect system information from compromised machines. It establishes persistence by creating scheduled tasks, with task creation tailored to the victim system’s operating system version. For defense evasion and reduced user visibility, it hides the Windows console window created during execution by invoking the GetConsoleWindow and ShowWindow APIs.
IMAPLoader has been delivered in targeted intrusion activity through strategic website compromise and drive-by style infection chains attributed to CURIUM. It has also been associated with malicious Excel document delivery using AppDomainManager injection in Tortoiseshell operations. The malware fits within broader Iranian espionage tradecraft focused on covert access, victim profiling, and data theft against selected targets rather than indiscriminate mass infection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CURIUM has created dedicated email accounts for use with tools such as IMAPLoader.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
APT1 has created email accounts for later use in social engineering, phishing, and when registering domains. APT42 has created email accounts to use in spearphishing operations. Contagious Interview has created fake email accounts to correspond with social media accounts, fake LinkedIn personas, code repository accounts, and job announcements on development job board services.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
Cannon exfiltrates collected data over email via SMTP/S and POP3/S C2 channels... CURIUM has used IMAP and SMTPS for exfiltration via tools such as IMAPLoader... Kevin can send data from the victim host through a DNS C2 channel... NightClub can use SMTP and DNS for file exfiltration and C2.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader malware that hides its console window using GetConsoleWindow and ShowWindow APIs.
Loader delivered via malicious Excel documents using AppDomainManager injection (as referenced in prior Iranian-linked campaigns).
A malware tool used by CURIUM in strategic website compromise operations and for exfiltration over IMAP and SMTPS channels.
Tool/malware used with dedicated email accounts by CURIUM.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.