NEW: Group Profiler — instant APT intel lookup. Try it →

RTM

G0048 Russia MITRE ATT&CK →

Overview

RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name (RTM).

Naming & attribution

RTM is tracked under 1 names across the industry. It uses 7 documented ATT&CK techniques — more than 20% of the 174 groups tracked here. Activity attributed since at least 2015.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
RTMFaou, M. and Boutin, J

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Naikon China — 4 shared techniques (24% overlap)
  • Elderwood China — 3 shared techniques (23% overlap)
  • APT19 China — 5 shared techniques (22% overlap)
  • Machete — 3 shared techniques (20% overlap)
  • PLATINUM — 3 shared techniques (20% overlap)
  • PROMETHIUM — 3 shared techniques (20% overlap)

Malware families with current indicators

One family attributed to RTM, carrying 2 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • RTM 2 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

TTPs — 7 techniques across 5 tactics

Initial Access

Execution

Persistence

Stealth

  • T1574.001 DLL

Command and Control

Tools & malware (1)

RTM

Reporting (1)