Description
IMAPLoader is a .NET based loader exclusively associated with the CURIUM intrusion set since at least 2022. It leverages email protocols for command and control and payload delivery, which hides its traffic inside legitimate mailbox activity.
Stats
- First seen
- June 2024
- Last seen
- September 2026
MITRE ATT&CK techniques
9 techniques across 5 tactics.
Associated groups
Alert name variants
| Alert Name |
|---|
| Win32.Trojan.Imaploader |