RTM

MISP
Tipo:
Unknown
Paese:
Unknown
Prima attivita:
Unknown
Dettagli:

There are several groups actively and profitably targeting businesses in Russia. A trend that we have seen unfold before our eyes lately is these cybercriminals’ use of simple backdoors to gain a foothold in their targets’ networks. Once they have this access, a lot of the work is done manually, slowly getting to understand the network layout and deploying custom tools the criminals can use to steal funds from these entities. Some of the groups that best exemplify these trends are Buhtrap, Cobalt and Corkow.
The group discussed in this white paper is part of this new trend. We call this new group RTM; it uses custom malware, written in Delphi, that we cover in detail in later sections. The first trace of this tool in our telemetry data dates back to late 2015. The group also makes use of several different modules that they deploy where appropriate to their targets. They are interested in users of remote banking systems (RBS), mainly in Russia and neighboring countries.

MITRE ATT&CK: View on MITRE
Tecniche Utilizzate (7)
ID ATT&CK Tattiche
T1102.001 Dead Drop Resolver -
T1189 Drive-by Compromise -
T1204.002 Malicious File -
T1219.002 Remote Desktop Software -
T1547.001 Registry Run Keys / Startup Folder -
T1566.001 Spearphishing Attachment -
T1574.001 DLL -
Alias (105)
G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048 G0048
Malware Utilizzato (1)
Metadata
ID: 240
Created: 13/01/2026 17:48
Updated: 07/03/2026 04:00