RMOT
- Malware type
- downloader, dropper
- Profile updated
- 2026-07-07 14:39:17
Targeted industries: retail-and-hospitality
Targeted regions: country_code:mo
Context
According to Trellix, this is a first-stage, powershell-based malware dropped via Excel/VBS. It is able to establish a foothold and exfiltrate data. Targets identified include hotels in Macao.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Ps1.Rmot (report)
- trellix.com — Suspected Darkhotel Apt Activity Update (report)