RTM Locker has been identified as a private ransomware-as-a-service operation that uses affiliates under tightly controlled rules while expanding beyond Windows to target VMware ESXi environments with a dedicated Linux encryptor. Researchers said the group appears primarily financially motivated, communicates in both Russian and English, and avoids victims in CIS countries and some sensitive sectors to reduce publicity and law-enforcement attention. In ESXi intrusions, the malware targets virtual machines directly, appends the .RTM extension to encrypted files, and leaves ransom notes titled !!! Warning !!!, with attacks also linked to data theft for double extortion.
Technical analysis of the Windows locker showed the malware repeatedly prompts for elevated privileges through UAC, kills selected processes and services, deletes shadow copies, clears event logs, encrypts files across mounted volumes using multithreaded IOCP-based routines, and then self-deletes. Reporting also tied the operation to a private affiliate model that may include former Conti-linked actors, while an internal dispute connected to the Russia-Ukraine war allegedly led to a server leak, reinforcing indications of Russia-linked membership and a geographically dispersed group.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Trellix described Read The Manual (RTM) Locker as a private ransomware-as-a-service operation using affiliates under strict rules intended to avoid publicity and law-enforcement attention. The report also detailed the Windows locker’s behavior, including repeated UAC elevation prompts, process and service termination, shadow copy deletion, event log clearing, multithreaded encryption, and self-deletion.
Quorum Cyber reported that RTM Locker had moved beyond a previously observed Windows encryptor and was deploying a Linux encryptor crafted to target virtual machines on VMware ESXi servers. The attacks used double extortion, appended the ".RTM" extension to encrypted files, and dropped ransom notes named "!!! Warning !!!".
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 52 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.