RTM

MITRE ATT&CK: S0148 View on attack.mitre.org

Aliases: Redaman, RTM

First seen
2015-08-01 00:00:00
Malware type
trojan, credential-stealer
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:56:10

Targeted industries: financial-services

Targeted regions: country_code:ru

Context

RTM is custom malware written in Delphi. It is used by the group of the same name (RTM). Newer versions of the malware have been reported publicly as Redaman.

Detection coverage

  • 702 Sigma rules

Malware & tools used

  • Bypass User Account Control (attack-pattern)
  • Remote Access Tools (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Clipboard Data (attack-pattern)
  • Keylogging (attack-pattern)
  • Dynamic Resolution (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Compression (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Peripheral Device Discovery (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Dynamic Data Exchange (attack-pattern)
  • Code Signing (attack-pattern)
  • Virtualization/Sandbox Evasion (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Modify Registry (attack-pattern)
  • Dead Drop Resolver (attack-pattern)
  • Native API (attack-pattern)
  • Automated Collection (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Install Root Certificate (attack-pattern)
  • Web Protocols (attack-pattern)
  • Rundll32 (attack-pattern)

Used by threat actors

  • RTM (threat-actor)

Related threat objects

  • RTM (malware)

Reports & references

  • ESET — Read The Manual (report)
  • Palo Alto Unit 42 — Russian Language Malspam Pushing Redaman Banking Malware (report)
  • MITRE ATT&CK — S0148 (report)

External references