The Iranian threat actor known asΒ TortoiseshellΒ has been attributed to a new wave of watering hole attacks that are designed to deploy a malware dubbed IMAPLoader.
"IMAPLoader is a .NET malware that has the ability to fingerprint victim systems using native Windows utilities and acts as a downloader for further payloads," the PwC Threat Intelligence teamΒ saidΒ in a Wednesday analysis.
"It uses