Also known as: G0048
RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name (RTM). (Citation: ESET RTM Feb 2017)
Executive Summary
RTM, also known as G0048, is a cybercriminal group that has been active since at least 2015, primarily targeting users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name to compromise victim systems. RTM's motivations and goals are not fully understood, but their actions suggest a financial motivation.
Goals & Targeting
RTM's strategic objectives and targeting profile suggest a focus on financial gain, potentially through the theft of sensitive financial information or the disruption of financial services. The group's targeting of remote banking systems in Russia and neighboring countries implies a regional focus, possibly due to the group's geographical location or linguistic expertise. Typical victims of RTM's attacks are likely to be financial institutions, organizations operating in the financial sector, or individuals with access to sensitive financial information.
Enhanced Description
Despite the available information, there are still gaps in our understanding of RTM's operations and motivations. Further research and analysis are needed to fully comprehend the group's goals, targeting profile, and potential connections to other threat actors. Nevertheless, the available data suggests that RTM is a significant threat to organizations operating in the financial sector, particularly those with a presence in Russia and neighboring countries.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
RTM's campaign patterns and operational tempo are not well understood, but their use of tailored Trojans and spear-phishing attacks suggests a level of planning and coordination. The group's targeting of remote banking systems in Russia and neighboring countries implies a regional focus, possibly due to the group's geographical location or linguistic expertise. Notable past operations include the reported attacks on financial institutions in Russia and neighboring countries, which suggest a level of success in the group's campaigns.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data on RTM is moderate, based on the limited information available from public sources. There are gaps in our understanding of the group's motivations, goals, and connections to other threat actors, which limits our ability to provide a comprehensive assessment of the threat. Further research and analysis are needed to fully comprehend RTM's operations and potential impact on organizations.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
7
Techniques
1
Tools
0
Campaigns
0
IOCs
0
Observed Data
5
Tactics