RTM Locker, also known as Read The Manual Locker, is a ransomware operation associated with a ransomware-as-a-service model. It has been observed deploying both Windows and Linux encryptors, including a Linux variant tailored to VMware ESXi environments where it targets virtual machines on hypervisors. Reporting also places RTM Locker among ransomware families that adopted Babuk-derived ESXi code, reflecting broader reuse of leaked ransomware source code to accelerate Linux and virtualization-focused development.
RTM Locker conducts double-extortion attacks, combining file encryption with theft of victim data for coercion. In Windows intrusions, the malware seeks administrative privileges, repeatedly prompting for elevation when necessary, then terminates selected processes and services, deletes shadow copies, clears event logs, and encrypts files across accessible local and remote volumes. It has also been observed mounting otherwise unmounted partitions to expand encryption coverage, using multithreaded encryption, changing the desktop wallpaper, and self-deleting after execution. In ESXi-focused attacks, the operation deploys a Linux encryptor specifically intended to impact virtualized enterprise infrastructure.
The malware’s behavior indicates deployment late in the intrusion lifecycle after attackers already possess substantial access to the victim environment. Successful compromises can affect enterprise data, including business records and credentials, and the operation threatens publication of stolen information if victims do not comply. RTM Locker has been described as opportunistic in victim selection for some campaigns, while the broader operation reportedly maintains affiliate rules and exclusions intended to reduce law-enforcement attention. The group has been linked to financially motivated cybercrime activity and has reportedly recruited affiliates, including individuals associated with other major ransomware ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The one-but-last action the locker performs wipes the System, Application, and Security logs from the machine.
Defense Evasion Techniques: T1070.004 – Indicator Removal: File Deletion
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows ransomware used in a private RaaS model. It encrypts files across local and mounted volumes, appends a random 64-character extension, drops a ransom note, changes the wallpaper, deletes shadow copies, clears Windows event logs, terminates processes and services that may hinder encryption, and self-deletes after execution. The operation also supports double extortion by claiming stolen data is stored on attacker servers.
A ransomware family mentioned as part of the Babuk-descended ESXi locker ecosystem.
Ransomware referenced as adding Linux variants to expand attack surface.
A ransomware family observed adopting leaked Babuk code for ESXi encryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.