IMAPLoader Malware Linked to Iranian Threat Actor

The Iranian threat actor known as Tortoiseshell, also tracked by names such as Crimson Sandstorm, Imperial Kitten, TA456, and Yellow Liderc, has been attributed to a new wave of watering hole attacks involving the deployment of a .NET malware named IMAPLoader.

Active since at least 2018, Tortoiseshell has a history of strategic website compromises, with recent attacks targeting the maritime, shipping, and logistics sectors in the Mediterranean.

IMAPLoader, a replacement for a previous Python-based IMAP implant, acts as a downloader for next-stage payloads. It uses email as a command and control channel, executing payloads from email attachments and deploying through new service deployments. The threat actor has been linked to the Islamic Revolutionary Guard Corps (IRGC) and has targeted various industries, including shipping, logistics, and financial services companies in Israel.

The latest attacks, observed between 2022 and 2023, involve embedding malicious JavaScript in compromised legitimate websites to gather visitor details. If a victim is deemed high-value, IMAPLoader is deployed as a follow-on payload.

The malware queries specific IMAP email accounts, checking a misspelled mailbox folder "Recive" for executables in message attachments. Additionally, an alternate attack chain uses a Microsoft Excel decoy document to initiate a multi-stage process for IMAPLoader delivery and execution, showcasing the threat actor's diverse tactics and techniques.

Who is Tortoiseshell APT?

Tortoiseshell is an Advanced Persistent Threat (APT) group that is believed to be of Iranian origin. APT groups are typically state-sponsored cyber threat actors that conduct long-term and sophisticated cyber-espionage campaigns. These groups often have specific strategic goals and are known for using advanced techniques to compromise and infiltrate their targets.

Tortoiseshell has been active since at least 2018 and is associated with the Islamic Republic of Iran. The group has targeted various sectors, including shipping, logistics, financial services, and other industries. It has a history of using strategic website compromises to distribute malware and has been linked to the Islamic Revolutionary Guard Corps (IRGC), a branch of the Iranian military.

Tortoiseshell's tactics involve using watering hole attacks, where they compromise legitimate websites to target visitors with malware, and deploying sophisticated malware like IMAPLoader to achieve their objectives. The group's activities have been monitored and reported on by various cybersecurity researchers and organizations in the field.

November 14, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.