RTM
MITRE ATT&CK: S0148 View on attack.mitre.org
Aliases: Redaman, RTM
- First seen
- 2015-08-01 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:56:10
Targeted industries: financial-services
Targeted regions: country_code:ru
Context
RTM is custom malware written in Delphi. It is used by the group of the same name (RTM). Newer versions of the malware have been reported publicly as Redaman.
Detection coverage
- 702 Sigma rules
Malware & tools used
- Bypass User Account Control (attack-pattern)
- Remote Access Tools (attack-pattern)
- Windows Command Shell (attack-pattern)
- Clipboard Data (attack-pattern)
- Keylogging (attack-pattern)
- Dynamic Resolution (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Compression (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Peripheral Device Discovery (attack-pattern)
- System Time Discovery (attack-pattern)
- Dynamic Data Exchange (attack-pattern)
- Code Signing (attack-pattern)
- Virtualization/Sandbox Evasion (attack-pattern)
- Scheduled Task (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Modify Registry (attack-pattern)
- Dead Drop Resolver (attack-pattern)
- Native API (attack-pattern)
- Automated Collection (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Install Root Certificate (attack-pattern)
- Web Protocols (attack-pattern)
- Rundll32 (attack-pattern)
Used by threat actors
- RTM (threat-actor)
Related threat objects
- RTM (malware)
Reports & references
- ESET — Read The Manual (report)
- Palo Alto Unit 42 — Russian Language Malspam Pushing Redaman Banking Malware (report)
- MITRE ATT&CK — S0148 (report)