ATT&CKSoftwareImminent Monitor

Imminent Monitor

S0434

Tool.View on attack.mitre.org

About this tool

Imminent Monitor was a commodity remote access tool (RAT) offered for sale from 2012 until 2019, when an operation was conducted to take down the Imminent Monitor infrastructure. Various cracked versions and variations of this RAT are still in circulation.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1021.001
Remote Desktop Protocol

Imminent Monitor has a module for performing remote desktop access.

T1027
Obfuscated Files or Information

Imminent Monitor has encrypted the spearphish attachments to avoid detection from email gateways; the debugger also encrypts information before sending to the C2.

T1041
Exfiltration Over C2 Channel

Imminent Monitor has uploaded a file containing debugger logs, network information and system information to the C2.

T1056.001
Keylogging

Imminent Monitor has a keylogging module.

T1057
Process Discovery

Imminent Monitor has a "Process Watcher" feature to monitor processes in case the client ever crashes or gets closed.

T1059
Command and Scripting Interpreter

Imminent Monitor has a CommandPromptPacket and ScriptPacket module(s) for creating a remote shell and executing scripts.

T1070.004
File Deletion

Imminent Monitor has deleted files related to its dynamic debugger feature.

T1083
File and Directory Discovery

Imminent Monitor has a dynamic debugging feature to check whether it is located in the %TEMP% directory, otherwise it copies itself there.

T1106
Native API

Imminent Monitor has leveraged CreateProcessW() call to execute the debugger.

T1123
Audio Capture

Imminent Monitor has a remote microphone monitoring capability.

T1125
Video Capture

Imminent Monitor has a remote webcam monitoring capability.

T1140
Deobfuscate/Decode Files or Information

Imminent Monitor has decoded malware components that are then dropped to the system.

T1496.001
Compute Hijacking

Imminent Monitor has the capability to run a cryptocurrency miner on the victim machine.

T1555.003
Credentials from Web Browsers

Imminent Monitor has a PasswordRecoveryPacket module for recovering browser passwords.

T1564.001
Hidden Files and Directories

Imminent Monitor has a dynamic debugging feature to set the file attribute to hidden.

View all 16 procedure examples

Groups that use it2

Campaigns0

None recorded.

References1

  1. Imminent Unit42 Dec2019 Open source
    Unit 42. (2019, December 2). Imminent Monitor – a RAT Down Under. Retrieved May 5, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.