RTM — Ransomware Profile
RTM is a financially motivated, Russian-speaking cybercriminal group active since at least late 2015, named by ESET in its February 2017 white paper "Read The Manual" after the custom Delphi banking trojan it operates. It targets accounting staff at businesses using remote banking systems and 1C:Enterprise software, mainly in Russia and neighbouring countries, substituting payment details or moving funds manually through remote-access tools such as LiteManager and RMS. In a campaign that entered its active phase in December 2020, Kaspersky and Group-IB observed the group pairing the trojan with a previously unseen ransomware they named Quoter against Russian transport and financial organisations, adding encryption and leak-based extortion to its payment fraud. No vendor has publicly placed the operators in a specific country - the evidence is linguistic rather than geographic - and Trellix has told reporters there is no relationship between Quoter and the unrelated 2023 "RTM Locker" ransomware-as-a-service, so the two RTM names should not be assumed to be one operation.Also tracked as
G0048
Tools & malware
- RTM Banking Trojan