Site icon TheCyberThrone

RTM Locker – RaaS Provider

Advertisements

Researchers have spotted a new RaaS provider group named Read The Manual (RTM) Locker. A typical affiliate-based model that forces its affiliates to follow strict rules, including leave notifications and minimal activity within a certain duration, failing to which their accounts may be locked or removed.

RTM Locker is a typical RaaS offering, which provides a web panel to its affiliates to manage their attack campaigns. The panel provides details about the rules, targets, and suggested attack methods.  

Advertisements

To avoid detection, affiliates are urged to avoid attacks on hospitals, morgues, and COVID-19 vaccine-related firms. Attacks on vital infrastructure, law enforcement agencies, and other major corporations are also mentioned in its exclusion list. If attacked, affiliates are forced to remove all traces of this malware and negotiate with the victims on a separate platform.

RTM Locker operators have laid down an additional set of professional rules for affiliates to follow.

RTM Locker is highly focused on staying away from the attention of security agencies. Strict rules would ensure that only dedicated adversaries are attracted to this malware.

Advertisements

The self-destructive nature of RTM Locker and the wipeout of logs make it a tough game to crack for security professionals.

Exit mobile version