RTM Locker is a ransomware family observed as part of the broader expansion of Linux and VMware ESXi-targeting extortion malware. It has been identified among ransomware families whose ESXi lockers descend from the leaked Babuk source code, indicating code reuse from the 2021 Babuk leak and placing it within the trend of lower-barrier development of Linux-focused ransomware tooling. RTM Locker has also been reported among ransomware families adding Linux variants during the 2023 increase in enterprise-focused ransomware activity. High-confidence public reporting in this context supports RTM Locker’s classification as a ransomware/extortion actor or family using Babuk-derived ESXi locker code, but does not provide sufficiently corroborated detail on its operators, victimology, geographic origin, specific targets, or distinct tradecraft beyond Linux/ESXi ransomware capability and code lineage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware family/group cited as a Babuk ESXi source-code descendant.
Ransomware operation referenced as adding Linux variants and as an emerging operation claiming exfiltration prior to encryption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.