Imminent Monitor was a commodity remote access tool (RAT) offered for sale from 2012 until 2019, when an operation was conducted to take down the Imminent Monitor infrastructure. Various cracked versions and variations of this RAT are still in circulation.
| Technique | Procedure example |
|---|---|
| T1021.001 Remote Desktop Protocol |
Imminent Monitor has a module for performing remote desktop access. |
| T1027 Obfuscated Files or Information |
Imminent Monitor has encrypted the spearphish attachments to avoid detection from email gateways; the debugger also encrypts information before sending to the C2. |
| T1041 Exfiltration Over C2 Channel |
Imminent Monitor has uploaded a file containing debugger logs, network information and system information to the C2. |
| T1056.001 Keylogging |
Imminent Monitor has a keylogging module. |
| T1057 Process Discovery |
Imminent Monitor has a "Process Watcher" feature to monitor processes in case the client ever crashes or gets closed. |
| T1059 Command and Scripting Interpreter |
Imminent Monitor has a CommandPromptPacket and ScriptPacket module(s) for creating a remote shell and executing scripts. |
| T1070.004 File Deletion |
Imminent Monitor has deleted files related to its dynamic debugger feature. |
| T1083 File and Directory Discovery |
Imminent Monitor has a dynamic debugging feature to check whether it is located in the %TEMP% directory, otherwise it copies itself there. |
| T1106 Native API |
Imminent Monitor has leveraged CreateProcessW() call to execute the debugger. |
| T1123 Audio Capture |
Imminent Monitor has a remote microphone monitoring capability. |
| T1125 Video Capture |
Imminent Monitor has a remote webcam monitoring capability. |
| T1140 Deobfuscate/Decode Files or Information |
Imminent Monitor has decoded malware components that are then dropped to the system. |
| T1496.001 Compute Hijacking |
Imminent Monitor has the capability to run a cryptocurrency miner on the victim machine. |
| T1555.003 Credentials from Web Browsers |
Imminent Monitor has a PasswordRecoveryPacket module for recovering browser passwords. |
| T1564.001 Hidden Files and Directories |
Imminent Monitor has a dynamic debugging feature to set the file attribute to hidden. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.