Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Our Research and Intelligence Fusion Team have been tracking the Gozi variant RM3 for close to 30 months... a deep dive technical analysis of the RM3 variant.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Otherwise, the banking malware was configured as an advanced infostealer, designed to steal data and intercept all keyboard interactions.
It’s worth noting that the mail module is an underrated feature that can provide a huge amount of information to a TA
One critical aspect of any banking malware is the ability to hook into a browser so as to inject fakes and replacers in financial institution websites. | RM3 implements an SSL Proxy and so is really effective at intercepting POST requests performed by the user.
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RM3 is described as an advanced Gozi/ISFB banking malware variant targeting financial institutions, especially in Oceania and Europe. It supports modular loading, credential theft, keylogging, web injects, SSL/HTTP(S) interception, hidden VNC, SOCKS proxying, desktop recording, and a persistent remote shell, and the report notes operators appear to be shifting from fraud toward ransomware-oriented bot triage and lateral movement.
Mentioned only in related content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.