Threat group.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1102.001 Dead Drop Resolver |
RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names. |
| T1189 Drive-by Compromise |
RTM has distributed its malware via the RIG and SUNDOWN exploit kits, as well as online advertising network |
| T1204.002 Malicious File |
RTM has attempted to lure victims into opening e-mail attachments to execute malicious code. |
| T1219.002 Remote Desktop Software |
RTM has used a modified version of TeamViewer and Remote Utilities for remote access. |
| T1547.001 Registry Run Keys / Startup Folder |
RTM has used Registry run keys to establish persistence for the RTM Trojan and other tools, such as a modified version of TeamViewer remote desktop software. |
| T1566.001 Spearphishing Attachment |
RTM has used spearphishing attachments to distribute its malware. |
| T1574.001 DLL |
RTM has used search order hijacking to force TeamViewer to load a malicious DLL. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.