ATT&CKReferencesESET RTM Feb 2017

ESET RTM Feb 2017

Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples33

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareRTM

RTM strings, network data, configuration, and modules are encrypted with a modified RC4 algorithm.

T1027.015
Compression
MalwareRTM

RTM has been delivered to targets as various archive files including ZIP, 7-ZIP, and RAR.

T1033
System Owner/User Discovery
MalwareRTM

RTM can obtain the victim username and permissions.

T1053.005
Scheduled Task
MalwareRTM

RTM tries to add a scheduled task to establish persistence.

T1056.001
Keylogging
MalwareRTM

RTM can record keystrokes from both the keyboard and virtual keyboard.

T1057
Process Discovery
MalwareRTM

RTM can obtain information about process integrity levels.

T1059.003
Windows Command Shell
MalwareRTM

RTM uses the command line and rundll32.exe to execute.

T1070.004
File Deletion
MalwareRTM

RTM can delete all files created during its execution.

T1070.009
Clear Persistence
MalwareRTM

RTM has the ability to remove Registry entries that it created for persistence.

T1082
System Information Discovery
MalwareRTM

RTM can obtain the computer name, OS version, and default language identifier.

T1102.001
Dead Drop Resolver
MalwareRTM

RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names. RTM has also hidden Pony C2 server IP addresses within transactions on the Bitcoin and Namecoin blockchain.

T1102.001
Dead Drop Resolver
GroupRTM

RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names.

T1105
Ingress Tool Transfer
MalwareRTM

RTM can download additional files.

T1106
Native API
MalwareRTM

RTM can use the FindNextUrlCacheEntryA and FindFirstUrlCacheEntryA functions to search for specific strings within browser history.

T1112
Modify Registry
MalwareRTM

RTM can delete all Registry entries created during its execution.

T1113
Screen Capture
MalwareRTM

RTM can capture screenshots.

T1115
Clipboard Data
MalwareRTM

RTM collects data from the clipboard.

T1119
Automated Collection
MalwareRTM

RTM monitors browsing activity and automatically captures screenshots if a victim browses to a URL matching one of a list of strings.

T1120
Peripheral Device Discovery
MalwareRTM

RTM can obtain a list of smart card readers attached to the victim.

T1124
System Time Discovery
MalwareRTM

RTM can obtain the victim time zone.

T1189
Drive-by Compromise
GroupRTM

RTM has distributed its malware via the RIG and SUNDOWN exploit kits, as well as online advertising network Yandex.Direct.

T1218.011
Rundll32
MalwareRTM

RTM runs its core DLL file using rundll32.exe.

T1219
Remote Access Tools
MalwareRTM

RTM has the capability to download a VNC module from command and control (C2).

T1518
Software Discovery
MalwareRTM

RTM can scan victim drives to look for specific banking software on the machine to determine next actions.

T1518.001
Security Software Discovery
MalwareRTM

RTM can obtain information about security software on the victim.

T1547.001
Registry Run Keys / Startup Folder
MalwareRTM

RTM tries to add a Registry Run key under the name "Windows Update" to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupRTM

RTM has used Registry run keys to establish persistence for the RTM Trojan and other tools, such as a modified version of TeamViewer remote desktop software.

T1548.002
Bypass User Account Control
MalwareRTM

RTM can attempt to run the program as admin, then show a fake error message and a legitimate UAC bypass prompt to the user in an attempt to socially engineer the user into escalating privileges.

T1553.002
Code Signing
MalwareRTM

RTM samples have been signed with a code-signing certificates.

T1553.004
Install Root Certificate
MalwareRTM

RTM can add a certificate to the Windows store.

T1559.002
Dynamic Data Exchange
MalwareRTM

RTM can search for specific strings within browser tabs using a Dynamic Data Exchange mechanism.

T1571
Non-Standard Port
MalwareRTM

RTM used Port 44443 for its VNC module.

T1573.001
Symmetric Cryptography
MalwareRTM

RTM encrypts C2 traffic with a custom RC4 variant.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.