Imminent Monitor
MITRE ATT&CK: S0434 View on attack.mitre.org
Aliases: Imminent Monitor
- First seen
- 2012-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 2 (2 malicious)
- Last IoC activity
- 2025-05-09 15:21:19
- Profile updated
- 2026-07-07 15:06:49
Context
Imminent Monitor was a commodity remote access tool (RAT) offered for sale from 2012 until 2019, when an operation was conducted to take down the Imminent Monitor infrastructure. Various cracked versions and variations of this RAT are still in circulation.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to Imminent Monitor (S0434). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | ee5b17af1bea3ce53b9a6bb09c21f634b9465fe505a01177b9eb33943f3021d3 | 2025-05-09 | 1 |
| file sample | 1729029868dd861d25f54bfcd0d7fd6d58578134bd41099c24152ff60c8a9b9bc1cc86e9bc989... | 2024-10-15 | 1 |
Detection coverage
- 423 Sigma rules
Malware & tools used
- Native API (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Keylogging (attack-pattern)
- File Deletion (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Process Discovery (attack-pattern)
- Command and Scripting Interpreter (attack-pattern)
- Video Capture (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- Compute Hijacking (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Audio Capture (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- File and Directory Discovery (attack-pattern)
Used by threat actors
Reports & references
- Palo Alto Unit 42 — Imminent Monitor A Rat Down Under (report)
- MITRE ATT&CK — S0434 (report)
- imminentmethods.info (report)