Imminent Monitor
Imminent Monitor is a commercial .NET remote access trojan (RAT), also described as remote control software, with the string "Imminent-Monitor-Client-Watermark" observed in payloads and an official website referenced as imminentmethods.net. The malware has been delivered via multiple infection chains, including Excel 4.0 (XLM) macro-enabled .xls documents that downloaded a disguised MSI installer executed with msiexec, which dropped an obfuscated .NET loader in %temp%, established persistence with a startup LNK, used InstallUtil.exe in the execution chain, and connected to the C2 domain linkadrum.nl. Proofpoint also observed TA2541 using DiscordApp URLs linking to compressed files that delivered Imminent Monitor in late 2021, and noted scheduled-task and registry-based persistence in those campaigns. TA2541 has targeted aviation, aerospace, transportation, manufacturing, and defense organizations, while APT-C-36 has been reported to have obtained and used a modified variant of Imminent Monitor.
Capabilities directly described in the content include remote webcam monitoring, remote microphone monitoring, keylogging, remote desktop access, browser password recovery via a PasswordRecoveryPacket module, and remote shell/script execution via CommandPromptPacket and ScriptPacket modules. The malware can decode components and drop them to the system, upload a file containing debugger logs, network information, and system information to C2, set file attributes to hidden as part of a dynamic debugging feature, delete files related to that debugger feature, disable Windows Task Manager, and use CreateProcessW() to execute the debugger. MITRE-style references in the content associate Imminent Monitor (S0434) with audio capture, keylogging, exfiltration over the C2 channel, and remote desktop functionality.
High-confidence indicators and artifacts mentioned in the content include hxxps://jplymell.com/dmc/InvoiceAug5e1063535cb7f5c06328ac2cd66114327.pdf, the C2 domain linkadrum.nl, the dropped file 033ventdata.exe, the path %temp%\ProtectedModuleHost.exe, and the watermark string "Imminent-Monitor-Client-Watermark."
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
beginning in late 2021, Proofpoint observed this group begin using DiscordApp URLs linking to a compressed file which led to either AgentTesla or Imminent Monitor.
APT-C-36 obtained and used a modified variant of Imminent Monitor.
Techniques & procedures
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
1 technique
Resource Development
Initial Access
3 techniques
Initial Access
TA2541 uses themes related to aviation, transportation, and travel. When Proofpoint first started tracking this actor, the group sent macro-laden Microsoft Word attachments that downloaded the RAT payload. The group pivoted, and now they more frequently send messages with links to cloud services such as Google Drive hosting the payload.
When Proofpoint first started tracking this actor, the group sent macro-laden Microsoft Word attachments that downloaded the RAT payload... Proofpoint has also observed this actor leverage attachments in emails. For example, the threat actor may send compressed executables such as RAR attachments with an embedded executable containing URL to CDNs hosting the malware payload.
Execution
5 techniques
Execution
TA2541 has also established persistence by creating scheduled tasks... In recent campaigns, vjw0rm and STRRAT also leveraged task creation... Scheduled Task: schtasks.exe /Create /TN "Updates\BQVIiVtepLtz" /XML C:\Users\[User]\AppData\Local\Temp\tmp7CF8.tmp
APT19 downloaded and launched code within a SCT file; APT32 used COM scriptlets to download Cobalt Strike beacons; APT37 used Ruby scripts to execute payloads; ArcaneDoor included the adversary executing command line interface (CLI) commands.
If executed, PowerShell pulls an executable from a text file hosted on various platforms such as Pastetext, Sharetext, and GitHub. The threat actor executes PowerShell into various Windows processes and queries Windows Management Instrumentation (WMI) for security products such as antivirus and firewall software, and attempts to disable built-in security protections.
Persistence
2 techniques
Persistence
Privilege Escalation
2 techniques
Privilege Escalation
Stealth
4 techniques
Stealth
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
Agent Tesla has created hidden folders. AppleJeus has added a leading . to plist filenames, unlisting them from the Finder app and default Terminal directory listings. APT28 has saved files with hidden file attributes. FIN13 has created hidden files and folders within a compromised Linux system /tmp directory and also used attrib.exe to hide gathered local host information.
Credential Access
2 techniques
Credential Access
Discovery
2 techniques
Discovery
Lateral Movement
1 technique
Lateral Movement
Collection
3 techniques
Collection
Command and Control
3 techniques
Command and Control
TA2541 uses Virtual Private Servers as part of their email sending infrastructure and frequently uses Dynamic DNS (DDNS) for C2 infrastructure.
Exfiltration
1 technique
Exfiltration
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
Impact
1 technique
Impact
IOCs tracked for this family
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan used by TA2541 for remote control and information gathering; observed delivered via Discord-hosted archives and persisted via scheduled tasks and registry run keys.
A commodity remote access trojan/tool sold on underground forums that provides full remote administration (remote desktop, file/process/registry management, keylogging, webcam/microphone monitoring, password recovery) and includes stealth/persistence and AV-evasion features (crypter/FUD, hidden logs, process watcher, disabling Task Manager, hidden remote desktop). Later versions added a cryptocurrency miner.
Remote access trojan with functionality to disable Task Manager and hinder user response.
Imminent Monitor is a commercial remote control (RAT) tool delivered via Excel 4.0 macros that fetch a disguised MSI payload, drops a .NET executable, establishes persistence (LNK in Startup), injects a .NET PE via InstallUtil.exe, decompresses an embedded payload using 7z/LZMA, and connects to a C2 (e.g., linkadrum.nl) to provide full remote-control functionality.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.