Cyber Resilience

Threat actor · all actors

RTMG0048 unknown

aka RTM, G0048

Last updated: 2026-07-03

0attributed CVEs
13ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

[RTM](https://attack.mitre.org/groups/G0048) is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name ([RTM](https://attack.mitre.org/software/S0148)). (Citation: ESET RTM Feb 2017)

Source: MITRE ATT&CK

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
CM-210 / 1377%
CM-610 / 1377%
SI-310 / 1377%
SI-410 / 1377%
AC-49 / 1369%
CA-79 / 1369%
SC-78 / 1362%
CM-77 / 1354%
SI-26 / 1346%
SI-76 / 1346%
SI-105 / 1338%
SC-444 / 1331%
SI-84 / 1331%
RA-53 / 1323%
AC-32 / 1315%

Co-occurring actors

None.

Similar actors

Similar TTPs