Imminent Monitor

MITRE ATT&CK: S0434 View on attack.mitre.org

Aliases: Imminent Monitor

First seen
2012-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
2 (2 malicious)
Last IoC activity
2025-05-09 15:21:19
Profile updated
2026-07-07 15:06:49

Context

Imminent Monitor was a commodity remote access tool (RAT) offered for sale from 2012 until 2019, when an operation was conducted to take down the Imminent Monitor infrastructure. Various cracked versions and variations of this RAT are still in circulation.

Recent IoC activity

2 malicious indicators in Maltiverse are attributed to Imminent Monitor (S0434). The 2 most recently updated:

Detection coverage

  • 423 Sigma rules

Malware & tools used

  • Native API (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Keylogging (attack-pattern)
  • File Deletion (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Process Discovery (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • Video Capture (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • Compute Hijacking (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Audio Capture (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • File and Directory Discovery (attack-pattern)

Used by threat actors

Reports & references

  • Palo Alto Unit 42 — Imminent Monitor A Rat Down Under (report)
  • MITRE ATT&CK — S0434 (report)
  • imminentmethods.info (report)

External references