Netskope Threat Labs

IMAPLoader

ATP Sandbox Adv. Heuristics

IMAPLoader is a .NET based loader exclusively associated with the CURIUM intrusion set since at least 2022. It leverages email protocols for command and control and payload delivery, which hides its traffic inside legitimate mailbox activity.

First seen
June 2024
Last seen
September 2026

9 techniques across 5 tactics.

TA0002 Execution

TA0003 Persistence

  • T1543Create or Modify System Process

TA0005 Stealth

TA0007 Discovery

  • T1082System Information Discovery

TA0011 Command and Control

Alert Name
Win32.Trojan.Imaploader