Skulkin, O. (2019, August 5). Following the RTM Forensic examination of a computer infected with a banking trojan. Retrieved May 11, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1204.002 Malicious File |
GroupRTM | RTM has attempted to lure victims into opening e-mail attachments to execute malicious code. |
| T1219.002 Remote Desktop Software |
GroupRTM | RTM has used a modified version of TeamViewer and Remote Utilities for remote access. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupRTM | RTM has used Registry run keys to establish persistence for the RTM Trojan and other tools, such as a modified version of TeamViewer remote desktop software. |
| T1566.001 Spearphishing Attachment |
GroupRTM | RTM has used spearphishing attachments to distribute its malware. |
| T1574.001 DLL |
GroupRTM | RTM has used search order hijacking to force TeamViewer to load a malicious DLL. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.