logo

RM3 – Curiosities of the wildest banking malware

ID: bb1af9f6-f5e5-5d4b-948f-bbbce283b669

STIX ID: report--bb1af9f6-f5e5-5d4b-948f-bbbce283b669

Feed Name: Fox-IT blog

Threat Score
78/100

Date Published: 2021-05-04

Date Updated: 2026-04-27

...
...

This report analyzes the Gozi ISFB RM3 banking malware variant over ~30 months, detailing its PX file format, modular architecture (bl.dll, explorer.dll, rt.dll, netwrk.dll, browser hooks, keylog, VNC, socks, cmdshell), distribution channels (malspam, Spelevo), geographic targeting (primarily Australia/New Zealand, UK, Germany, Italy), and operational changes including AES migration and potential pivot toward ransomware-style lateral movement; it also provides IoCs (module hashes, campaign IDs), config samples, and TTPs for detection and tracking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.