An international law enforcement operation disrupted the Imminent Monitor remote access trojan (RAT), a malware tool marketed online as legitimate remote administration software but widely used for cybercrime. Researchers at Palo Alto Networks Unit 42 said they collected more than 65,000 samples and observed over 115,000 attacks tied to the malware, which included stealth and persistence features, antivirus-evasion tooling, hidden keylogging, and later cryptocurrency-mining capability. Investigators linked the malware’s developer, known as "Shockwave™", to Australia and referred the case to the Australian Federal Police, which worked with partners including the FBI and Canada’s CRTC to support Operation Cepheus and disable the RAT’s licensing infrastructure.
The takedown exposed purchaser records and triggered enforcement against suspected users, with authorities reporting 85 warrants, 434 device seizures, and 13 arrests. In the UK, that investigation led to the conviction of Scott Cowley of St Helens, Merseyside, who was sentenced to two years in prison after forensic analysis found he had used Imminent Monitor to hijack the webcams of three women and secretly record them in their bedrooms. The case underscored how a commodity RAT sold to thousands of customers was used not only for intrusion and surveillance, but also for sexual abuse and other criminal activity.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
Imminent Monitor added support for third-party plugins, expanding its functionality. An early plugin enabled covert webcam monitoring while turning off the webcam light.
Shockwave™ began selling Imminent Monitor on online forums and through a website in April 2013. The malware was marketed as a remote access tool but included capabilities associated with criminal abuse.
A developer using the alias “Shockwave™” registered the domain imminentmethods[.]info, an early infrastructure component associated with Imminent Monitor. Unit 42 identified this as part of the malware’s origins.
Scott Cowley, a 27-year-old from St Helens, Merseyside, was jailed for two years for using the Imminent Monitor RAT to hijack webcams and secretly film women in their bedrooms. The sentence followed his conviction on computer misuse and sexual offence charges.
Liverpool Crown Court found Scott Cowley guilty of computer misuse and sexual offences for using Imminent Monitor to spy on three women through their webcams and record them. Forensic examination of his laptop found the malware and covert recordings of the victims.
Scott Cowley was arrested in November after purchaser records seized during the Imminent Monitor investigation led authorities to him. Investigators linked him to the malware through purchase records and later forensic evidence from his laptop.
International law enforcement agencies dismantled the infrastructure behind Imminent Monitor in November as part of Operation Cepheus. The operation executed 85 warrants, seized 434 devices, made 13 arrests, and disrupted the RAT’s licensing system and distribution network.
Palo Alto Networks Unit 42 referred the identity and activity of the actor behind Imminent Monitor, “Shockwave™,” to the Australian Federal Police Cybercrime Operations teams. This referral supported a broader international investigation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.