LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0048: RTM

RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name (RTM). [1]

EnterpriseG0048GroupObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

RTM matters because it represents financially motivated intrusion activity focused on remote banking users, with documented use of the RTM banking Trojan and related behaviors spanning phishing or drive-by access, user-executed malicious files, Windows persistence, DLL abuse, legitimate remote desktop software, and web-based C2 redirection. For leaders, the decision value is not “track a named group” in isolation; it is whether banking, finance, and payment-adjacent workflows have enough email, endpoint, web, and remote-access visibility to detect and contain credential or remote-control activity before it affects fraud risk and business continuity.

Executive priority

Prioritize RTM-relevant coverage where users interact with remote banking systems or sensitive financial operations. Executives should ask whether controls can prove: suspicious attachments are filtered and investigated, browser/web exposure is monitored, unauthorized remote desktop tools are governed, Windows startup persistence is visible, and incident responders can quickly determine whether a banking Trojan or remote-control channel is present. This object has no official ATT&CK detection text and no group-level platform list, so risk decisions should be based on the related techniques and the organization’s own exposure to remote banking processes.

Technical view

SOC and IR teams should validate coverage against the documented relationships: S0148 RTM malware, T1566.001 Spearphishing Attachment, T1189 Drive-by Compromise, T1204.002 Malicious File, T1547.001 Registry Run Keys / Startup Folder, T1574.001 DLL abuse, T1219.002 Remote Desktop Software, and T1102.001 Dead Drop Resolver. Because the related malware and several techniques include Windows, prioritize Windows endpoint evidence for process execution, file creation, DLL loading, registry run key or startup folder changes, and remote desktop software execution. Network teams should validate visibility into outbound connections to legitimate external web services that may act as dead drop resolvers, while email and web teams should confirm retention and investigation workflows for attachments, links, and browsing events associated with suspicious execution.

Likely telemetry

  • Email security logs and message metadata for attachments delivered to targeted users
  • Endpoint process execution, file creation, and command-line telemetry
  • Windows registry monitoring for Run keys and startup folder changes
  • DLL load and suspicious library path telemetry where available
  • Web proxy, DNS, and network egress logs for browsing, drive-by exposure, and outbound C2 discovery patterns

Detection direction

  • Do not rely only on malware names; map detections to the related behaviors because RTM activity may be observed through phishing, malicious file execution, persistence, remote access tooling, or C2 redirection.
  • Tune phishing and malicious attachment detections around user execution outcomes, not just message delivery, to reduce false positives and identify successful compromise paths.
  • Baseline approved remote desktop and support tools, then alert on unexpected installation, execution, or outbound sessions from finance or banking-related endpoints.
  • Validate Windows persistence detections for Run keys and startup folders, including user-context persistence that may be missed by privilege-focused monitoring.
  • Review network monitoring assumptions for T1102.001: legitimate web services can mask C2 resolver behavior, so detections may require correlation with endpoint compromise signals rather than simple domain blocking.

Mitigation priorities

  • Start with business-process scoping: identify users and endpoints that access remote banking systems and ensure they receive stronger monitoring and response prioritization.
  • Harden email and web controls against suspicious attachments, social engineering, and drive-by exposure, while maintaining evidence retention for investigations.
  • Enforce application control or software governance for remote desktop/support tools so approved use is distinguishable from adversary use.
  • Improve Windows endpoint hardening and monitoring for startup persistence and DLL abuse, especially on finance-related workstations.
  • Maintain incident response playbooks for suspected banking Trojan activity that include credential protection, remote access review, endpoint isolation, and validation of financial transaction workflows.
Additional notes and limits

ATT&CK describes RTM as a cybercriminal group active since at least 2015 and primarily interested in users of remote banking systems in Russia and neighboring countries, using the RTM Trojan. The most useful defensive context comes from the supplied relationships to RTM malware and techniques for initial access, execution, persistence, C2, and remote desktop software. This take intentionally frames RTM as a coverage-validation scenario for financial workflows rather than asserting current targeting of any organization.

The supplied group object has no official ATT&CK detection guidance, no group-level tactics, and no group-level platforms. Platform and tactic context is inferred only from the supplied related software and technique relationships. The source set is limited to MITRE’s object data and cited external references; local exposure, telemetry quality, and control effectiveness must be confirmed by the organization.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

RTM

RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name (RTM). [1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

7 rows
DomainIDNameRelationship / procedure
EnterpriseT1189Drive-by Compromise

RTM has distributed its malware via the RIG and SUNDOWN exploit kits, as well as online advertising network Yandex.Direct.[1][2]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

RTM has used Registry run keys to establish persistence for the RTM Trojan and other tools, such as a modified version of TeamViewer remote desktop software.[1][3]

EnterpriseT1574.001DLLSub-technique

RTM has used search order hijacking to force TeamViewer to load a malicious DLL.[3]

EnterpriseT1204.002Malicious FileSub-technique

RTM has attempted to lure victims into opening e-mail attachments to execute malicious code.[3]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

RTM has used spearphishing attachments to distribute its malware.[3]

EnterpriseT1219.002Remote Desktop SoftwareSub-technique

RTM has used a modified version of TeamViewer and Remote Utilities for remote access.[3]

EnterpriseT1102.001Dead Drop ResolverSub-technique

RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names.[1]

Associated objects

Groups, software, and campaigns

MalwareEnterprise

S0148: RTM

RTM is custom malware written in Delphi. It is used by the group of the same name (RTM). Newer versions of the malware have been reported publicly as Redaman.[1][2]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
6e23f5d998ab142f...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle6e23f5d998ab…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    ESET RTM Feb 2017

    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

    Open source URL
  2. [2]
    ESET Buhtrap and Buran April 2019

    ESET Research. (2019, April 30). Buhtrap backdoor and Buran ransomware distributed via major advertising platform. Retrieved May 11, 2020.

    Open source URL
  3. [3]
    Group IB RTM August 2019

    Skulkin, O. (2019, August 5). Following the RTM Forensic examination of a computer infected with a banking trojan. Retrieved May 11, 2020.

    Open source URL
  4. [4]
    ESET RTM Feb 2017

    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

    Open source URL
  5. [5]
    ESET RTM Feb 2017

    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

    Open source URL
  6. [6]
    RTM

    (Citation: ESET RTM Feb 2017)

  7. [7]
    RTM

    (Citation: ESET RTM Feb 2017)

  8. [8]
    RTM

    (Citation: ESET RTM Feb 2017)

  9. [9]
    mitre-attackG0048
    Open source URL
  10. [10]
    mitre-attackG0048
    Open source URL
  11. [11]
    mitre-attackG0048
    Open source URL
  12. [12]
    ESET Buhtrap and Buran April 2019

    ESET Research. (2019, April 30). Buhtrap backdoor and Buran ransomware distributed via major advertising platform. Retrieved May 11, 2020.

    Open source URL
  13. [13]
    ESET RTM Feb 2017

    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

    Open source URL
  14. [14]
    ESET RTM Feb 2017

    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

    Open source URL
  15. [15]
    ESET RTM Feb 2017

    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

    Open source URL
  16. [16]
    ESET RTM Feb 2017

    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

    Open source URL
  17. [17]
    Group IB RTM August 2019

    Skulkin, O. (2019, August 5). Following the RTM Forensic examination of a computer infected with a banking trojan. Retrieved May 11, 2020.

    Open source URL
  18. [18]
    Group IB RTM August 2019

    Skulkin, O. (2019, August 5). Following the RTM Forensic examination of a computer infected with a banking trojan. Retrieved May 11, 2020.

    Open source URL
  19. [19]
    Group IB RTM August 2019

    Skulkin, O. (2019, August 5). Following the RTM Forensic examination of a computer infected with a banking trojan. Retrieved May 11, 2020.

    Open source URL
  20. [20]
    Group IB RTM August 2019

    Skulkin, O. (2019, August 5). Following the RTM Forensic examination of a computer infected with a banking trojan. Retrieved May 11, 2020.

    Open source URL
  21. [21]
    Group IB RTM August 2019

    Skulkin, O. (2019, August 5). Following the RTM Forensic examination of a computer infected with a banking trojan. Retrieved May 11, 2020.

    Open source URL
  22. [22]
    Group IB RTM August 2019

    Skulkin, O. (2019, August 5). Following the RTM Forensic examination of a computer infected with a banking trojan. Retrieved May 11, 2020.

    Open source URL
  23. [23]
    Group IB RTM August 2019

    Skulkin, O. (2019, August 5). Following the RTM Forensic examination of a computer infected with a banking trojan. Retrieved May 11, 2020.

    Open source URL
  24. [24]
    Group IB RTM August 2019

    Skulkin, O. (2019, August 5). Following the RTM Forensic examination of a computer infected with a banking trojan. Retrieved May 11, 2020.

    Open source URL
  25. [25]
    Group IB RTM August 2019

    Skulkin, O. (2019, August 5). Following the RTM Forensic examination of a computer infected with a banking trojan. Retrieved May 11, 2020.

    Open source URL
  26. [26]
    ESET RTM Feb 2017

    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

    Open source URL
  27. [27]
    ESET RTM Feb 2017

    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

    Open source URL
  28. [28]
    ESET RTM Feb 2017

    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

    Open source URL
  29. [29]
    ESET RTM Feb 2017

    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.