RTM

G0048

Threat group.View on attack.mitre.org

About this group

RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name (RTM).

Techniques used7

Procedure examples7

TechniqueProcedure example
T1102.001
Dead Drop Resolver

RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names.

T1189
Drive-by Compromise

RTM has distributed its malware via the RIG and SUNDOWN exploit kits, as well as online advertising network Yandex.Direct.

T1204.002
Malicious File

RTM has attempted to lure victims into opening e-mail attachments to execute malicious code.

T1219.002
Remote Desktop Software

RTM has used a modified version of TeamViewer and Remote Utilities for remote access.

T1547.001
Registry Run Keys / Startup Folder

RTM has used Registry run keys to establish persistence for the RTM Trojan and other tools, such as a modified version of TeamViewer remote desktop software.

T1566.001
Spearphishing Attachment

RTM has used spearphishing attachments to distribute its malware.

T1574.001
DLL

RTM has used search order hijacking to force TeamViewer to load a malicious DLL.

Software1

Campaigns0

None recorded.

References1

  1. ESET RTM Feb 2017 Open source
    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.