THREAT_ACTOR · G0048
RTM
Also known as: RTM
Profile
RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name (RTM).
MITRE ATT&CK ↗Techniques
7 ATT&CK techniques attributed to this actor.
Software
1 malware/tools attributed to this actor.
RTM
Related corpus activity
4,206 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to RTM.
Showing the top 30 by severity of 4,206.