NEW: Group Profiler — instant APT intel lookup. Try it →

← threatfilter.dev / all groups / RTM

RTM

G0048 Russia MITRE ATT&CK →

Overview

RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name (RTM).

TTPs — 7 techniques across 5 tactics

Initial Access

Execution

Persistence

Stealth

  • T1574.001 DLL

Command and Control

Tools & malware (1)

RTM

Reporting (1)