RTM

MITRE ATT&CK: G0048 View on attack.mitre.org

Aliases: RTM

First seen
2015-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 11:57:28

Targeted industries: financial-services

Targeted regions: country_code:ru

Context

RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name (RTM).

Detection coverage

  • 207 Sigma rules

Malware & tools used

  • Drive-by Compromise (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • DLL (attack-pattern)
  • Malicious File (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Remote Desktop Software (attack-pattern)
  • Dead Drop Resolver (attack-pattern)
  • RTM (malware)

Reports & references

  • ESET — Read The Manual (report)
  • MITRE ATT&CK — G0048 (report)

External references