Imminent Monitor, also known as IM-RAT, is a Windows remote access trojan that was marketed online as a legitimate remote administration tool and has been sold since 2012. In practice it provides covert remote-control and surveillance capabilities commonly associated with commodity RAT malware. Documented functionality includes browser password recovery, keylogging, remote shell access through command and script execution modules, webcam monitoring, collection of network and system information, and upload of collected data to command-and-control infrastructure. It also includes process-watching functionality to monitor client execution and can decode additional components and drop them onto the victim system during operation.
Imminent Monitor incorporates multiple defense-evasion and operational-support features. Reported behaviors include setting files to hidden attributes, disabling Windows Task Manager, using native Windows process-creation APIs to launch components such as its debugger, and deleting files associated with debugging activity. Its ability to recover browser-stored passwords and log keystrokes makes it suitable for credential theft and broader post-compromise surveillance.
The malware has been used by both individual criminal operators and organized intrusion activity. A modified variant has been used by APT-C-36, and it has also appeared in financially motivated phishing campaigns attributed to TA2541, including delivery through links to compressed payloads. Public reporting has also tied Imminent Monitor to invasive webcam-spying abuse cases. The malware targets Windows systems and is associated with commodity cybercrime operations as well as opportunistic espionage-style remote access activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
beginning in late 2021, Proofpoint observed this group begin using DiscordApp URLs linking to a compressed file which led to either AgentTesla or Imminent Monitor.
APT-C-36 obtained and used a modified variant of Imminent Monitor.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
TA2541 uses themes related to aviation, transportation, and travel. When Proofpoint first started tracking this actor, the group sent macro-laden Microsoft Word attachments that downloaded the RAT payload. The group pivoted, and now they more frequently send messages with links to cloud services such as Google Drive hosting the payload.
When Proofpoint first started tracking this actor, the group sent macro-laden Microsoft Word attachments that downloaded the RAT payload... Proofpoint has also observed this actor leverage attachments in emails. For example, the threat actor may send compressed executables such as RAR attachments with an embedded executable containing URL to CDNs hosting the malware payload.
TA2541 has also established persistence by creating scheduled tasks... In recent campaigns, vjw0rm and STRRAT also leveraged task creation... Scheduled Task: schtasks.exe /Create /TN "Updates\BQVIiVtepLtz" /XML C:\Users\[User]\AppData\Local\Temp\tmp7CF8.tmp
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries.
If executed, PowerShell pulls an executable from a text file hosted on various platforms such as Pastetext, Sharetext, and GitHub. The threat actor executes PowerShell into various Windows processes and queries Windows Management Instrumentation (WMI) for security products such as antivirus and firewall software, and attempts to disable built-in security protections.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
TA2541 uses Virtual Private Servers as part of their email sending infrastructure and frequently uses Dynamic DNS (DDNS) for C2 infrastructure.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
49 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan sold online as a purported legitimate remote administration tool, used to hijack webcams, spy on victims, disable webcam indicator lights during monitoring, and in one version mine cryptocurrency on victims' PCs.
Remote access trojan used by TA2541 for remote control and information gathering; observed delivered via Discord-hosted archives and persisted via scheduled tasks and registry run keys.
Remote access trojan that uploads debugger logs, network information, and system information to C2.
Remote access trojan that deletes files related to its debugging feature.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.