What the Australian RAT Investigation Teaches About Safety-Led Digital Forensics
Historical allegations are attributed to the AFP and should not be read as findings of guilt.
The Australian Federal Police investigation into Imminent Monitor exposed more than a prolific remote-access trojan. It demonstrated how relatively inexpensive surveillance software can be deployed as an instrument of domestic abuse, sexual offending, financial crime and persistent personal control.
In July 2022, the AFP announced charges against an Australian man it alleged had created and administered Imminent Monitor after first developing the tool as a teenager. According to the AFP, the software was sold to more than 14,500 people across 128 countries. Investigators identified 201 Australian purchasers, including people recorded as respondents to domestic violence orders and a person registered as a child sex offender.
Those figures describe the alleged criminal operation reported by law enforcement; they do not establish the current status or outcome of every proceeding. This article uses the matter as a documented example of technology-facilitated abuse and does not make findings about the guilt of any named person.
The enduring lesson is operational. When someone suspects that a phone, computer, account, vehicle or connected device is being used to monitor them, the first action should not automatically be to locate and delete an application. Personal safety, preservation of potential evidence and containment of continuing access must be considered together.
Important Notice: Personal Safety and Evidence Preservation
Where unlawful monitoring is suspected and formal evidence may be required, avoid unplanned changes. Removing an application, resetting hardware, running consumer clean-up utilities, closing accounts or otherwise modifying the system can disturb information needed by police, a court, an employer or another authorised process.
Where interruption could provoke a dangerous response, protect the person before the technology. From a device and location believed to be safe, seek emergency assistance, specialist domestic-violence support, legal advice, police help or another authorised pathway. Avoid challenging the suspected monitor using equipment that could still be observed.
- Immediate danger in Australia: call 000. For 24-hour domestic and family violence support, contact 1800RESPECT on 1800 737 732.
- Emergency assistance in the UAE: Police can be reached on 999 and Ambulance on 998. The Dubai Foundation for Women and Children can be contacted on 800 111.
- NSI Global enquiries: call 1300 000 NSI (674) in Australia or +971 (0)4 409 6824 in the UAE.
What Was Imminent Monitor?
Imminent Monitor was described by the AFP as a remote-access trojan, commonly shortened to RAT. Once installed, such software can allow a remote operator to control functions of a compromised computer without the user’s informed authorisation.
The AFP alleged that Imminent Monitor could enable purchasers to:
- View or steal personal information;
- Monitor typed content through keylogging;
- Activate webcams and microphones;
- Observe activity on the compromised computer; and
- Exercise remote control while attempting to avoid detection.
Law-enforcement agencies dismantled the Imminent Monitor infrastructure in 2019 as part of an international operation. The AFP subsequently alleged that its Australian administrator had received between approximately $300,000 and $400,000 from selling the tool for about $35 per licence.
The low purchase price matters. Technology-facilitated surveillance is not confined to highly resourced intelligence services or bespoke commercial spyware. Commodity malware, shared passwords, linked accounts, location-sharing functions and ordinary remote-administration tools can all be misused by people with relatively little technical expertise.
Why the Case Matters to Domestic and Family Violence
Technology-facilitated abuse is broader than malware. The eSafety Commissioner describes it as abuse involving digital technology, including monitoring, stalking, harassment, impersonation and patterns of coercive control.
An abusive person may combine several channels:
- Knowledge of passwords, recovery questions or device passcodes;
- Access to an Apple, Google, Microsoft, email or social-media account;
- Location sharing through family, safety or navigation services;
- Linked messaging sessions or cloud backups;
- Vehicle, Bluetooth, tracker or smart-home access;
- Legitimate parental-control, workplace or device-management software used without authority; and
- Malicious software installed on a phone or computer.
This is why unusual battery drain, heat, data use or device behaviour cannot prove that spyware is present. Conversely, a device that behaves normally cannot be declared free from surveillance. Some monitoring leaves few user-visible indicators; other apparent symptoms have ordinary technical explanations.
The practical question is therefore not simply, “Is there spyware on this phone?” It is, “What credible surveillance pathways fit the reported behaviour, and which devices, accounts, services and connected systems fall within the lawful investigative scope?”
Safety, Evidence and Account Security Can Point in Different Directions
The correct first response depends on the outcome that matters most at that moment.
| Situation | Immediate objective | Action that may create additional risk |
| Immediate danger or coercive control | Reach a safe location and trusted support without alerting the suspected operator | Confronting the person or visibly changing monitored settings without a safety plan |
| Potential evidence for police or court | Preserve the device, associated accounts and relevant history | Uninstalling applications, resetting, deleting or conducting repeated self-tests |
| Continuing account compromise | Establish a trusted communication and recovery pathway | Entering replacement credentials on a device that may capture them |
| Corporate or executive exposure | Activate legal, security and incident-response governance | Sending the device through routine help-desk or repair processes without preservation instructions |
| General prevention with no suspected incident | Apply current security controls and reduce attack surface | Treating every unexplained symptom as proof of deliberate surveillance |
When more than one objective applies, the response should be coordinated. A device may need to remain operational temporarily for safety or investigative reasons, while a separate trusted device is used for communications and account recovery. In another matter, rapid isolation may be necessary because remote deletion or continuing commercial harm outweighs the value of continued observation.
There is no universal rule that every suspected device should be switched off, placed in a shielded pouch or disconnected from all networks. Each measure changes the device’s state and may affect connectivity, volatile data, timestamps, alerts or the suspected operator’s behaviour. The decision should follow risk triage and the authorised evidentiary purpose.
Build an Initial Factual Brief Without Self-Testing
If circumstances permit, write down what is already known from memory using equipment the suspected person cannot access. Relevant details may include:
- Why surveillance is suspected;
- Dates, locations and relevant incidents;
- Information another person appeared to know unexpectedly;
- People who could handle the equipment or obtain its unlock code;
- Sign-in warnings, recovery messages or other security notifications previously seen;
- Unusual applications, permissions, administrator profiles or linked sessions already noticed;
- The device model, operating system and principal accounts associated with it;
- Any intervention already performed, such as an update, reset or credential change; and
- Any anticipated police report, court dispute, workplace process or application for protective orders.
This is not an instruction to repeatedly open suspicious applications, search through the suspected operator’s accounts, install scanning tools or attempt attribution. Those actions can increase risk, create legal problems or change the evidence that an authorised examiner may later need to interpret.
Actions to Avoid When Safety or Evidence May Be Involved
Until an appropriate pathway has been chosen, avoid:
- Factory-resetting, trading in, repairing or disposing of the suspected device;
- Installing several consumer spyware detectors or “cleaner” applications;
- Erasing messages or remotely stored information, closing accounts or terminating linked access;
- Entering newly created credentials into the device under suspicion;
- Restoring backups or transferring the device’s contents without considering evidentiary effects;
- Allowing an ordinary repair provider to make undocumented changes;
- Confronting the suspected operator; and
- Publicly identifying an alleged perpetrator without an appropriate legal or police process.
Urgent protection sometimes outweighs preservation. When an intervention cannot safely be deferred, document the action, responsible person, time and reason when circumstances allow. Contemporaneous notes or photographs can add context, although neither substitutes for an authorised preservation process.
What an Authorised Forensic Examination May Cover
A proportionate spyware investigation begins with authority and purpose. The examiner should establish who owns the device and accounts, who can authorise access, what question must be answered and whether the work relates to personal safety, legal proceedings, an employment matter or corporate incident response.
Depending on the risk profile and available authority, examination may address:
- Device state and configuration: installed software, permissions, profiles, administrator rights, security settings and relevant operating-system artefacts.
- Accounts and cloud services: sign-in history, linked sessions, recovery settings, forwarding rules, shared data and available provider records.
- Communications and applications: relevant application artefacts, databases, logs, notifications and associated metadata.
- Network and connected systems: routers, remote-access services, trackers, vehicles, wearable devices or smart-home platforms where they fall within scope.
- Chronology and correlation: whether independent records support a timeline of access, monitoring, changes or data movement.
- Preservation and reporting: documentation of handling, acquisition, validation, findings, limitations and unresolved uncertainty.
The scope must be broad enough to cover the credible risk profile. A narrow examination of installed applications could miss a compromised account, linked device, cloud-sharing arrangement or off-device surveillance channel. At the same time, the work should remain relevant, proportionate and legally authorised.
What a Forensic Examination Cannot Guarantee
No examiner should promise to detect every form of surveillance, recover every deleted artefact or identify the operator conclusively.
A negative device result means that no reportable spyware or anomaly was identified within the agreed scope, methods, device state and available data. It does not prove that surveillance never occurred. Relevant material may have been deleted, encrypted, stored by a provider, located on another device or outside the commissioned period.
Attribution also requires caution. An artefact may indicate that an account or application was used, but it may not establish who was physically responsible. Conclusions should distinguish observed facts, technical inference and information supplied by the client.
Likewise, a forensic report is not automatically admissible or decisive in every proceeding. Its value depends on lawful authority, relevance, handling, methodology, documentation, examiner competence and the rules applicable to the particular forum.
How NSI Global Supports Authorised Spyware Matters
Through Forensic Spyware and Malware Detection, NSI Global can assess authorised devices and defined indicators against a lawful examination brief. If the concern may extend across an organisation, Digital Forensic Incident Response can bring together evidence from devices, user identities, mail systems, cloud platforms, endpoints and network records.
Matters involving anticipated proceedings may also require coordinated Litigation Support, legal notices, preservation instructions and an appropriate chain-of-custody process.
NSI Global does not accept every private engagement. Conflict checks, authority, engagement conditions and lawful-purpose requirements apply. For some sensitive personal matters, NSI Global may require an instruction or referral from legal counsel, law enforcement, a responsible case officer, a public authority, an insurer, a recognised support organisation or another properly authorised representative.
For current first-response guidance, read Spyware Concerns? Here’s How to Safeguard Your Phone and Computer. Separate prevention guidance is available for Android devices and Apple iPhones.
Frequently Asked Questions
Should I Remove Suspected Spyware Immediately?
Not automatically. Removal, resetting or account changes may destroy evidence or alert an abusive operator. If someone may be in danger, personal safety takes priority. Use a separate trusted device to obtain safety, legal, police or forensic advice before changing the suspected device when practicable.
Does Unexpected Battery Drain Prove That Spyware Is Installed?
No. Battery drain, heat, data consumption and crashes have many ordinary causes. They may justify further assessment when combined with stronger indicators, but they are not proof of spyware.
Can Surveillance Occur Without Spyware on the Device?
Yes. Monitoring may occur through compromised accounts, linked sessions, shared cloud services, location sharing, vehicle systems, trackers, routers, smart devices or legitimate management tools being used without authority.
Can a Clean Scan Prove That a Device Was Never Monitored?
No. A result is limited by the device state, available records, examination method, date range and scope. Some activity may leave limited artefacts or occur outside the examined device.
What Should I Do if I Am in Immediate Danger?
Move to a safer place and use trusted equipment where practicable. Australian emergency assistance is available through Triple Zero (000), while 1800RESPECT can be reached on 1800 737 732. In the UAE, the emergency numbers are 999 for Police and 998 for Ambulance. Preserving a device must never delay help needed to protect a person.
Sources and Further Reading
- Australian Federal Police – AFP Charges Man with Creating Global Spyware Tool
- eSafety Commissioner – Online Safety Checklist
- eSafety Commissioner – Collecting Evidence Safely
- eSafety Commissioner – Technology-Facilitated Abuse and Coercive Control
- 1800RESPECT – Device Safety
General information only: This article is not legal advice or an emergency-response service. Safety, evidence, privacy, surveillance and computer-access requirements depend on the facts and jurisdiction.