RMOT

Malware type
downloader, dropper
Profile updated
2026-07-07 14:39:17

Targeted industries: retail-and-hospitality

Targeted regions: country_code:mo

Context

According to Trellix, this is a first-stage, powershell-based malware dropped via Excel/VBS. It is able to establish a foothold and exfiltrate data. Targets identified include hotels in Macao.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Ps1.Rmot (report)
  • trellix.com — Suspected Darkhotel Apt Activity Update (report)

External references