RTM
MITRE ATT&CK: G0048 View on attack.mitre.org
Aliases: RTM
- First seen
- 2015-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 11:57:28
Targeted industries: financial-services
Targeted regions: country_code:ru
Context
RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name (RTM).
Detection coverage
- 207 Sigma rules
Malware & tools used
- Drive-by Compromise (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- DLL (attack-pattern)
- Malicious File (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Remote Desktop Software (attack-pattern)
- Dead Drop Resolver (attack-pattern)
- RTM (malware)
Reports & references
- ESET — Read The Manual (report)
- MITRE ATT&CK — G0048 (report)