AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
RTM
Aliases: None listed
RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name (RTM).
Open interactive actor investigation
ATT&CK techniques
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Vulnerability Research & Exploit Development · topic-matchScenario-based cyber risk assessment and treatment
Governance, Risk & Compliance (GRC) · topic-matchOperational resilience, continuity, crisis, and incident governance
Governance, Risk & Compliance (GRC) · topic-matchModule 6 — The Threat Actor Landscape
Cyber Threat Intelligence (CTI) · tactic-routeDisassembly, decompilation, and code-led analysis
Malware Analysis & Reverse Engineering · tactic-routeModule 5 — Threat hunting
Blue Team & Defensive Security · tactic-routeModule 4 — Web applications and APIs
Red Team & Offensive Security · tactic-routeModule 3 — Telemetry and logging architecture
Blue Team & Defensive Security · tactic-routeThreat modeling and secure architecture
Secure Code & Application Security · tactic-routeModule 5 — Cloud, containers, and Kubernetes
Red Team & Offensive Security · tactic-routeStatic triage: strings, imports, resources, and capabilities
Malware Analysis & Reverse Engineering · tactic-routeModule 4 — Detection engineering and detection as code
Blue Team & Defensive Security · tactic-route