Imminent Monitor, also known as IM-RAT, is a Windows remote-access trojan that was marketed as a legitimate remote administration tool and sold online from 2012 until its infrastructure was disrupted by an international law-enforcement operation. It provides remote control and surveillance functions, including webcam monitoring, keylogging, browser password recovery, remote shell access, and script execution. It can collect and upload system and network information to command-and-control infrastructure. The malware includes defense-evasion functionality, including setting file attributes to hidden, deleting artifacts associated with its debugging feature, disabling Windows Task Manager, and monitoring processes to maintain operation if its client is closed or crashes. Imminent Monitor has been used by cybercriminal purchasers for webcam surveillance and has been deployed by threat actors including APT-C-36 (Blind Eagle) and TA2541. Documented campaigns delivered it through phishing lures, including links to compressed archives hosted through cloud and messaging services. TA2541 targeted aviation, aerospace, transportation, manufacturing, and defense organizations, while APT-C-36 targeted organizations in Colombia and elsewhere in South America.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“In the past, we have observed that APT-C-36 makes use of RATs such as: ... Imminent Monitor ...”
beginning in late 2021, Proofpoint observed this group begin using DiscordApp URLs linking to a compressed file which led to either AgentTesla or Imminent Monitor.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
TA2541 uses themes related to aviation, transportation, and travel. When Proofpoint first started tracking this actor, the group sent macro-laden Microsoft Word attachments that downloaded the RAT payload. The group pivoted, and now they more frequently send messages with links to cloud services such as Google Drive hosting the payload.
When Proofpoint first started tracking this actor, the group sent macro-laden Microsoft Word attachments that downloaded the RAT payload... Proofpoint has also observed this actor leverage attachments in emails. For example, the threat actor may send compressed executables such as RAR attachments with an embedded executable containing URL to CDNs hosting the malware payload.
TA2541 has also established persistence by creating scheduled tasks... In recent campaigns, vjw0rm and STRRAT also leveraged task creation... Scheduled Task: schtasks.exe /Create /TN "Updates\BQVIiVtepLtz" /XML C:\Users\[User]\AppData\Local\Temp\tmp7CF8.tmp
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries.
If executed, PowerShell pulls an executable from a text file hosted on various platforms such as Pastetext, Sharetext, and GitHub. The threat actor executes PowerShell into various Windows processes and queries Windows Management Instrumentation (WMI) for security products such as antivirus and firewall software, and attempts to disable built-in security protections.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
TA2541 uses Virtual Private Servers as part of their email sending infrastructure and frequently uses Dynamic DNS (DDNS) for C2 infrastructure.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
50 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access tool previously used by APT-C-36.
Remote access trojan sold online as a purported legitimate remote administration tool, used to hijack webcams, spy on victims, disable webcam indicator lights during monitoring, and in one version mine cryptocurrency on victims' PCs.
Remote access trojan used by TA2541 for remote control and information gathering; observed delivered via Discord-hosted archives and persisted via scheduled tasks and registry run keys.
Remote access trojan that uploads debugger logs, network information, and system information to C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.