RTM
Overview
RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name (RTM).
Naming & attribution
RTM is tracked under 1 names across the industry. It uses 7 documented ATT&CK techniques — more than 20% of the 174 groups tracked here. Activity attributed since at least 2015.
| Name | First reported by |
|---|---|
| RTM | Faou, M. and Boutin, J |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
Malware families with current indicators
One family attributed to RTM, carrying 2 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- RTM 2 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
TTPs — 7 techniques across 5 tactics
Initial Access
-
T1189Drive-by Compromise -
T1566.001Spearphishing Attachment
Execution
-
T1204.002Malicious File
Persistence
-
T1547.001Registry Run Keys / Startup Folder
Stealth
-
T1574.001DLL
Command and Control
-
T1102.001Dead Drop Resolver -
T1219.002Remote Desktop Software
Tools & malware (1)
RTM
Reporting (1)
- Read The Manual: A Guide to the RTM Banking Trojan — Faou, M. and Boutin, J