RTM

Aliases: Redaman

First seen
2017-02-01 00:00:00
Malware type
trojan, credential-stealer
Family
Malware family
Profile updated
2026-07-07 12:56:07

Targeted industries: financial-services

Targeted regions: country_code:ru

Context

RTM Banker also known as Redaman was first blogged about in February 2017 by ESET. The malware is written in Delphi and shows some similarities (like process list) with Buhtrap. It uses a slightly modified version of RC4 to encrypt its strings, network data, configuration and modules, according to ESET.

Related threat objects

  • RTM (malware)

Reports & references

  • ESET — Read The Manual (report)
  • ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
  • Kaspersky — 101638 (report)
  • ESET — Buhtrap Backdoor Ransomware Advertising Platform (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Rtm (report)
  • youtube.com — Watch (report)
  • Palo Alto Unit 42 — Russian Language Malspam Pushing Redaman Banking Malware (report)
  • jonahacks.medium.com — Malware Analysis Manual Unpacking Of Redaman Ec1782352Cfb (report)
  • peppermalware.com — Brief Analysis Of Redaman Banking (report)

External references