Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: G0048

Description

RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name (RTM). (Citation: ESET RTM Feb 2017)

AI Analysis

· 1 month ago

Executive Summary

RTM, also known as G0048, is a cybercriminal group that has been active since at least 2015, primarily targeting users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name to compromise victim systems. RTM's motivations and goals are not fully understood, but their actions suggest a financial motivation.

Goals & Targeting

RTM's strategic objectives and targeting profile suggest a focus on financial gain, potentially through the theft of sensitive financial information or the disruption of financial services. The group's targeting of remote banking systems in Russia and neighboring countries implies a regional focus, possibly due to the group's geographical location or linguistic expertise. Typical victims of RTM's attacks are likely to be financial institutions, organizations operating in the financial sector, or individuals with access to sensitive financial information.

Enhanced Description

Despite the available information, there are still gaps in our understanding of RTM's operations and motivations. Further research and analysis are needed to fully comprehend the group's goals, targeting profile, and potential connections to other threat actors. Nevertheless, the available data suggests that RTM is a significant threat to organizations operating in the financial sector, particularly those with a presence in Russia and neighboring countries.

Key Capabilities

  • Trojan development and deployment
  • Spear-phishing and social engineering
  • Drive-by compromise and exploitation
  • DLL and registry manipulation
  • Remote desktop software exploitation

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion

ATT&CK Techniques

T1204.002
T1566.001
T1574.001
T1547.001
T1219.002
T1189
T1102.001

Software / Tooling

RTM Trojan
inter

Campaigns & Victims

RTM's campaign patterns and operational tempo are not well understood, but their use of tailored Trojans and spear-phishing attacks suggests a level of planning and coordination. The group's targeting of remote banking systems in Russia and neighboring countries implies a regional focus, possibly due to the group's geographical location or linguistic expertise. Notable past operations include the reported attacks on financial institutions in Russia and neighboring countries, which suggest a level of success in the group's campaigns.

IOC Patterns

  • Spear-phishing with malicious attachments
  • Drive-by compromise via exploited vulnerabilities
  • DLL and registry manipulation for persistence
  • Remote desktop software exploitation for lateral movement

Recommended Actions

  • Implement robust email security controls to detect and block spear-phishing attacks
  • Regularly update and patch software vulnerabilities to prevent drive-by compromise
  • Monitor system logs for suspicious activity, particularly related to DLL and registry manipulation
  • Implement robust privileged access management controls to prevent lateral movement

Suggested Tags

Cybercrime
Financial sector
Russia
Trojan

Confidence Assessment

The confidence level in the available data on RTM is moderate, based on the limited information available from public sources. There are gaps in our understanding of the group's motivations, goals, and connections to other threat actors, which limits our ability to provide a comprehensive assessment of the threat. Further research and analysis are needed to fully comprehend RTM's operations and potential impact on organizations.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. ESET RTM Feb 2017 — Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

Intel Summary

7

Techniques

1

Tools

0

Campaigns

0

IOCs

0

Observed Data

5

Tactics

Tags

Financial Targeting
Cybercrime
Financial sector
Russia
Trojan

Details

MITRE ID
G0048
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--c416b28c-103b-4df1-909e-78089a7e0e5f
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.