RTM Locker, also known as Read The Manual, is a financially motivated ransomware-as-a-service operation associated with the broader RTM cybercrime ecosystem. The group has evolved from earlier e-crime activity, including use of the RTM Banking Trojan against remote banking and accounting-related workflows, into enterprise ransomware operations. It has been observed recruiting affiliates, reportedly including individuals linked to the former Conti syndicate, and enforcing strict operational rules intended to reduce publicity and law-enforcement attention. RTM Locker conducts double-extortion attacks, combining file encryption with theft of victim data and threats of publication. The operation has targeted corporate environments opportunistically and indiscriminately, including VMware ESXi infrastructure through a Linux encryptor designed to impact virtual machines. Earlier reporting also identified a Windows encryptor. The group’s affiliate model includes victim-management workflows and timed data-release pressure, consistent with mature extortion operations. Observed tradecraft includes initial access through spam attachments themed as business documents and drive-by delivery in earlier RTM activity, followed by post-compromise deployment of ransomware after attackers have already obtained sufficient control of a victim environment. RTM Locker has sought administrative privileges, terminated selected processes and services, deleted shadow copies, cleared event logs, mounted otherwise unmounted partitions, enumerated processes, collected local data, encrypted files across local and remote drives, and self-deleted after execution. Activity mapped to ATT&CK includes process discovery, access token manipulation, native API execution, file deletion, event log clearing, service stopping, local data collection, and data encryption for impact. The group has reportedly excluded Commonwealth of Independent States victims and certain sensitive sectors from targeting, and available reporting indicates likely Russia-linked membership. Internal friction tied to the Russia-Ukraine war has also been noted. RTM Locker is best characterized as a Russia-linked cybercriminal ransomware operation focused on financial extortion rather than political objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A private ransomware-as-a-service operation using affiliates to conduct double-extortion attacks against corporate environments while trying to stay below the radar and avoid high-profile targets.
Ransomware and RaaS operations targeting VMware ESXi servers with a Linux encryptor, using double extortion and recruiting affiliates; the group is also described as historically targeting remote banking systems in Russia with the RTM Banking Trojan for financial gain.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.