Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareRTM | RTM strings, network data, configuration, and modules are encrypted with a modified RC4 algorithm. |
| T1027.015 Compression |
MalwareRTM | RTM has been delivered to targets as various archive files including ZIP, 7-ZIP, and RAR. |
| T1033 System Owner/User Discovery |
MalwareRTM | RTM can obtain the victim username and permissions. |
| T1053.005 Scheduled Task |
MalwareRTM | RTM tries to add a scheduled task to establish persistence. |
| T1056.001 Keylogging |
MalwareRTM | RTM can record keystrokes from both the keyboard and virtual keyboard. |
| T1057 Process Discovery |
MalwareRTM | RTM can obtain information about process integrity levels. |
| T1059.003 Windows Command Shell |
MalwareRTM | RTM uses the command line and rundll32.exe to execute. |
| T1070.004 File Deletion |
MalwareRTM | RTM can delete all files created during its execution. |
| T1070.009 Clear Persistence |
MalwareRTM | RTM has the ability to remove Registry entries that it created for persistence. |
| T1082 System Information Discovery |
MalwareRTM | RTM can obtain the computer name, OS version, and default language identifier. |
| T1102.001 Dead Drop Resolver |
MalwareRTM | RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names. RTM has also hidden Pony C2 server IP addresses within transactions on the Bitcoin and Namecoin blockchain. |
| T1102.001 Dead Drop Resolver |
GroupRTM | RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names. |
| T1105 Ingress Tool Transfer |
MalwareRTM | RTM can download additional files. |
| T1106 Native API |
MalwareRTM | RTM can use the |
| T1112 Modify Registry |
MalwareRTM | RTM can delete all Registry entries created during its execution. |
| T1113 Screen Capture |
MalwareRTM | RTM can capture screenshots. |
| T1115 Clipboard Data |
MalwareRTM | RTM collects data from the clipboard. |
| T1119 Automated Collection |
MalwareRTM | RTM monitors browsing activity and automatically captures screenshots if a victim browses to a URL matching one of a list of strings. |
| T1120 Peripheral Device Discovery |
MalwareRTM | RTM can obtain a list of smart card readers attached to the victim. |
| T1124 System Time Discovery |
MalwareRTM | RTM can obtain the victim time zone. |
| T1189 Drive-by Compromise |
GroupRTM | RTM has distributed its malware via the RIG and SUNDOWN exploit kits, as well as online advertising network |
| T1218.011 Rundll32 |
MalwareRTM | RTM runs its core DLL file using rundll32.exe. |
| T1219 Remote Access Tools |
MalwareRTM | RTM has the capability to download a VNC module from command and control (C2). |
| T1518 Software Discovery |
MalwareRTM | RTM can scan victim drives to look for specific banking software on the machine to determine next actions. |
| T1518.001 Security Software Discovery |
MalwareRTM | RTM can obtain information about security software on the victim. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRTM | RTM tries to add a Registry Run key under the name "Windows Update" to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupRTM | RTM has used Registry run keys to establish persistence for the RTM Trojan and other tools, such as a modified version of TeamViewer remote desktop software. |
| T1548.002 Bypass User Account Control |
MalwareRTM | RTM can attempt to run the program as admin, then show a fake error message and a legitimate UAC bypass prompt to the user in an attempt to socially engineer the user into escalating privileges. |
| T1553.002 Code Signing |
MalwareRTM | RTM samples have been signed with a code-signing certificates. |
| T1553.004 Install Root Certificate |
MalwareRTM | RTM can add a certificate to the Windows store. |
| T1559.002 Dynamic Data Exchange |
MalwareRTM | RTM can search for specific strings within browser tabs using a Dynamic Data Exchange mechanism. |
| T1571 Non-Standard Port |
MalwareRTM | RTM used Port 44443 for its VNC module. |
| T1573.001 Symmetric Cryptography |
MalwareRTM | RTM encrypts C2 traffic with a custom RC4 variant. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.