RMS

Aliases: Gussdoor, Remote Manipulator System, RuRAT

Malware type
rat
Family
Malware family
Last IoC activity
2026-07-22 01:43:19
Profile updated
2026-07-07 12:45:05

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services

Context

CyberInt states that Remote Manipulator System (RMS) is a legitimate tool developed by Russian organization TektonIT and has been observed in campaigns conducted by TA505 as well as numerous smaller campaigns likely attributable to other, disparate, threat actors. In addition to the availability of commercial licenses, the tool is free for non-commercial use and supports the remote administration of both Microsoft Windows and Android devices.

Exploited vulnerabilities

  • CVE-2017-0199 (vulnerability)

Reports & references

  • web.archive.org — Odinaff New Trojan Used High Level Financial Attacks (report)
  • Palo Alto Unit 42 — Unit 42 Title Gamaredon Group Toolset Evolution (report)
  • e.cyberint.com — Cyberint Legit%20Remote%20Access%20Tools%20Turn%20Into%20Threat%20Actors'%20Tools Report (report)
  • bitdefender.com — Curly Comrades New Threat Actor Targeting Geopolitical Hotbeds (report)
  • ssu.gov.ua — Technical%20Report%20Armagedon (report)
  • awakesecurity.com — Catching The White Stork In Flight (report)
  • Kaspersky — 114740 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Rms (report)
  • ics-cert.kaspersky.com — Kaspersky Attacks On Industrial Enterprises Using Rms And Teamviewer En (report)
  • bluevoyant.com — Mercenary Akula Hits Financial Institution (report)
  • blog.malwarebytes.com — Cve 2017 0199 Used To Deliver Modified Rms Agent Rat (report)
  • blog.yoroi.company — Ta505 Is Expanding Its Operations (report)

External references