RTM

S0148

Malware.View on attack.mitre.org

About this malware

RTM is custom malware written in Delphi. It is used by the group of the same name (RTM). Newer versions of the malware have been reported publicly as Redaman.

Techniques used38

Procedure examples38

TechniqueProcedure example
T1027
Obfuscated Files or Information

RTM strings, network data, configuration, and modules are encrypted with a modified RC4 algorithm.

T1027.015
Compression

RTM has been delivered to targets as various archive files including ZIP, 7-ZIP, and RAR.

T1033
System Owner/User Discovery

RTM can obtain the victim username and permissions.

T1036
Masquerading

RTM has been delivered as archived Windows executable files masquerading as PDF documents.

T1036.004
Masquerade Task or Service

RTM has named the scheduled task it creates "Windows Update".

T1053.005
Scheduled Task

RTM tries to add a scheduled task to establish persistence.

T1056.001
Keylogging

RTM can record keystrokes from both the keyboard and virtual keyboard.

T1057
Process Discovery

RTM can obtain information about process integrity levels.

T1059.003
Windows Command Shell

RTM uses the command line and rundll32.exe to execute.

T1070.004
File Deletion

RTM can delete all files created during its execution.

T1070.009
Clear Persistence

RTM has the ability to remove Registry entries that it created for persistence.

T1071.001
Web Protocols

RTM has initiated connections to external domains using HTTPS.

T1082
System Information Discovery

RTM can obtain the computer name, OS version, and default language identifier.

T1083
File and Directory Discovery

RTM can check for specific files and directories associated with virtualization and malware analysis.

T1102.001
Dead Drop Resolver

RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names. RTM has also hidden Pony C2 server IP addresses within transactions on the Bitcoin and Namecoin blockchain.

View all 38 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. ESET RTM Feb 2017 Open source
    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.
  2. Unit42 Redaman January 2019 Open source
    Duncan, B., Harbison, M. (2019, January 23). Russian Language Malspam Pushing Redaman Banking Malware. Retrieved June 16, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.