Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
The Danchev Interviews

RTM Locker interview: a ransomware actor on the RaaS market

Dancho DanchevBy Dancho DanchevAugust 21, 2026Updated:August 21, 2026No Comments13 Mins Read116 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
The Danchev Interviews, RTM Locker on the record. Confidential source Alex C., RTM Team, status unverified.
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

I have been reading Russian-speaking cybercrime forums for the better part of two decades, and one habit has never left me. When I ran the Astalavista security portal as a younger man, I sat down with someone from the scene every month, a researcher, a vendor, now and then a person on the wrong side of the law, and I asked them questions. Between 2003 and 2006 I published more than twenty of those interviews. This is the same exercise, carried over to Ransomnews and pointed at a harder subject.

The man on the other end of this one calls himself Alex C. He speaks for a group he calls RTM Team. Most readers will know the name in a different form, RTM Locker, the ransomware-as-a-service operation that Trellix documented in April 2023 and tied to the older Read The Manual crew, a Russian-speaking group with a past in banking malware. I am going to be careful with that label, because he was. He never once said RTM Locker to me. He said RTM Team, and he placed himself as one participant in it rather than the person who runs the locker. The distinction is his, and I am keeping it.

I reached him over Tox. I did not stumble onto him. For three years I have been pulling offline copies of forum communities and mining them for the contact details members leave lying around, and his was among them. I showed him my Tox ID, pointed him at my published work so he could satisfy himself that I am who I claim to be, and asked whether he would answer a set of questions. He read them, he answered, and he agreed to see them published.

One point about language, because it changes how you should read what follows. I put my questions to him in English. He replied in Russian. The translation here is mine, kept as close to his own phrasing as English will allow, including the places where he is vague, boastful, or plainly contradicts himself. I have left those in rather than tidy them away. What I have not done is verify him. I cannot confirm his role, the scale he describes, or that RTM Team and RTM Locker are the same thing beyond his word for it. Read what follows as testimony from inside a criminal world, not as fact I am standing behind.

Establishing contact

He gave me a name he had chosen for the occasion, then asked who I worked for. He also raised the subject of work against competing companies before I had put a single question to him about it.

Dancho Danchev: Who am I speaking to?

Alex C.: Good day. Let us say my name is Alex C. I represent RTM Team, which specialises in the field of security research.

Dancho Danchev: Are you familiar with my research and achievements throughout the years?

Alex C.: As for your work, I am not familiar with your interviews or your achievements, but it would be interesting to read them.

Dancho Danchev: Are you completely willing to give me this interview?

Alex C.: I am interested.

Dancho Danchev: Is there anything you want to ask me before we begin?

Alex C.: Are you an independent researcher, or do you actually work for some company?

Dancho Danchev: Is there a particular question you want me to ask you, or a particular topic you want covered?

Alex C.: We have no particular questions. I would suggest questions in the area of security, and also about our providing services to competing companies.

The interview

Dancho Danchev: What is your primary purpose for giving this interview? What do you hope to accomplish?

Alex C.: There are no particular goals. Maybe I will simply shed some light on the RaaS topic. We are probably striving to sharpen our skills in research work; our interest in it is not feigned.

Dancho Danchev: Do you agree to have me go public and publish the interview with your answers?

Alex C.: Yes, I agree.

Dancho Danchev: How did you get started in the cybercrime ecosystem?

Alex C.: We started out quite a long time ago, more than fifteen years now, back when home internet came in over the telephone line. At first I was simply curious how everything on the network worked. Evenings spent at the monitor led me to various forums where people discussed all sorts of ways of earning online; private messages and plain interest drew us into the dark net.

There were not nearly as many forums then as there are now. They offered all kinds of goods and services. We made many attempts to earn by buying material of one sort or another, and, frankly, it worked out fairly well; the security of the day was mediocre, you could say everything just flew. After a while more serious malware began to appear on the market, Zeus, SpyEye and the like. Digging through logs, we landed on several servers holding a great deal of compromising information, from personal data to scanned documents and credit cards. From that point the direction was clear. We began to study more closely how networks and servers work and where they are weak, to practise social engineering, to learn the various audit tools, and later to write our own.

Dancho Danchev: How would you describe yourself? A vendor of a service or a solution, an active threat actor, or a ransomware operator?

Alex C.: I am one of the group’s participants. I am not an operator of the ransomware programs; particular people handle those matters. You could say I am an enthusiast of security research with broadened means of monetisation.

Dancho Danchev: How did you get involved with computers?

Alex C.: What brought me into the computer world was the age of technological change itself, the arrival of the home PC and the coming of the internet. We landed, it seems to me, at the very best moment, when the network was only just gathering pace.

Dancho Danchev: How popular and far-reaching in the cybercrime ecosystem is what you are currently doing?

Alex C.: At one point, maybe four years ago, work in the security field was popular in general, with the arrival of a thing like RaaS. It was something new. The world was not ready for threats of that kind, and, as practice showed, many companies treated their own security very irresponsibly. Right now our activity is not as large in scale, but it still runs the way it did before. Lately, cases involving competing companies have been arriving more and more often, special orders, which is rather interesting.

Dancho Danchev: What are your current projects and future plans?

Alex C.: We are running several targeted campaigns, fairly interesting projects. We also scan the network and keep our lists, and here and there we wait for new releases around CVEs, local privilege escalation and remote code execution.

Dancho Danchev: Do you view yourself as a pure opportunist, a businessman, or do you hold any ideological justifications for your actions?

Alex C.: We have no ideological justifications as such. We enjoy our work; we found ourselves in it, with a lean toward business and toward making money.

Dancho Danchev: How do you compartmentalise your digital life as an operator from your personal, real-world life?

Alex C.: Personal life and work are not separated at all; you could say they are a single whole. The only thing is that the priority probably leans more toward work. The formula: a full personal life plus work you love.

Dancho Danchev: What is the biggest misconception the general public has about the people behind the screen in the cybercrime ecosystem?

Alex C.: One is that every cybercriminal earns a lot. Wandering the forums, you can get that impression, but in reality ninety percent of it is dust. Another is that behind the big breaches stand top-class hackers and elaborate schemes; in practice it is often far simpler than that.

“

Ninety percent of it is dust.

▮  Alex C., RTM Team  ·  on the myth of easy money

Dancho Danchev: Have you ever been scammed or ripped off by other actors within the underground community?

Alex C.: Yes, naturally. It happens often enough, because the communities are full of people chasing easy money. Usually, when you run a project or buy materials, tools and so on for the work, the budget always sets aside a sum for possible rip-offs, call it the accompanying financial damage. There were times when partners we had had long relationships with cheated us. That is the human factor. When a large sum lands on someone all at once, the temptation is great, and not everyone can cope with it.

Dancho Danchev: What is the most common, fundamental security failure you see in corporate networks today?

Alex C.: A careless attitude to how the network is built, software updated late, and, most important of all, the human factor. Companies are just as careless with their own specialists and underrate them; the ratio of pay to the area of responsibility simply does not add up.

Dancho Danchev: If paying ransoms were made globally illegal tomorrow, how would your business model pivot?

Alex C.: If payment were made illegal worldwide, revenue would certainly fall. But companies do not only pay because their network is paralysed or production has stopped or something else has happened; most companies pay when they have something to hide. Some are afraid of fines for storing information improperly, for a lax attitude to security regulations. They are also often afraid of what follows once data is published online, of what competitors will do, of the dark net and the resale of the data taken, and so on.

“

Most companies pay when they have something to hide.

▮  Alex C., RTM Team  ·  on why the ransom gets paid

Dancho Danchev: Where do you see the ransomware industry in five years? Will it consolidate, become more fragmented, or evolve into something entirely different?

Alex C.: I think that within five years the question of ransomware programs will be settled. This industry will not exist in the form it takes now, or the form it took three or four years ago. It seems to me all of it will evolve into something more closed and narrowly specialised. We will live and see; nothing lasts forever.

Dancho Danchev: How competitive is the ransomware landscape between different groups?

Alex C.: In truth the market is not all that big. The one thing is that a fair number of ransomware programs are appearing now, and not of the best quality. Mostly these are guys who have read the articles about the big payouts of years ago, downloaded the source of some basic locker, filed it into working order, and are waiting for a more or less average payment so they can ride off into the sunset with the money. Later those same guys rebrand and come back to the market anew.

Dancho Danchev: What does “retirement” or exit look like for people who leave this activity?

Alex C.: I have no idea how people retire or what it looks like. Personally, we have no set goal to earn a billion, or whatever the figure, and then go and rest. What drives us is more the thrill and the interest; the income is already a secondary matter. So I cannot really speak to the pension question.

Dancho Danchev: How might changes in cryptocurrency regulation or tracing capabilities affect operations?

Alex C.: Regulating cryptocurrency naturally complicates the process, but it does not solve it. We do not have a country called Earth with one territory and one set of laws. Dirty money is a story as old as the world. Where there is demand, there will be supply.

“

There is no country called Earth with one territory and one set of laws.

▮  Alex C., RTM Team  ·  on regulating cryptocurrency

Dancho Danchev: What question do you wish more interviewers or researchers would ask people in your position?

Alex C.: “What are your goals, and what drives you?”

Dancho Danchev: If you could speak directly to organisations that might become victims, what would you want them to hear?

Alex C.: Learn to take your internet security seriously. Run training among your staff on the basic rules of using the internet. Do not use pirated software. Update your software on time.

Dancho Danchev: What does “success” actually mean inside this world?

Alex C.: To me it is the ratio between the goals you set and the goals you reach.

After the conversation

A few things stayed with me once the answers stopped coming.

He is not selling a myth, and after twenty years of these conversations that is the detail I trust most. There is no genius here, no cinematic underground, no cause he wants me to admire. He describes a trade: patient, opportunistic, tolerant of loss, run for money by people who treat it as ordinary work. The operators who perform menace are usually the ones with the least behind them. The ones who describe a business, dull as it sounds, tend to be closer to the truth of how this actually happens.

Two of his answers deserve a second reading. The first is his claim that most companies pay over what a leak would expose, not over a frozen network. I have watched that change take hold across the last five years, the weapon moving from the encryption to the stolen data itself, and it is rare to hear someone on his side of it say so without dressing it up. The second is the line he drops, almost in passing, about special orders against competing companies. He does not linger on it. He does not have to. It is a reminder that a slice of this activity is not opportunistic extortion at all but paid sabotage, one business buying harm against another, and that corner of the market almost never shows up in public reporting or in the victim feeds the rest of us watch.

I would not take his forecast to the bank. Operators have been announcing the death of ransomware “in its current form” for as long as I have covered them, and the form keeps mutating instead of dying. But his sketch of the low end of the market, the men who read the old payout stories, buy a locker, take one average payment and rebrand, is the most honest thing he said, and it lines up with everything the numbers show.

The names will keep changing. RTM Team, RTM Locker, whatever comes after it. The leverage he keeps circling back to will not: access, stolen data, pressure, and a victim who is frightened of what comes next. That was the shape of this business before he entered it, and it will outlast whatever he says it becomes.

Notes and sources

  • Interview conducted over Tox in August 2026. Questions asked in English, answers given in Russian and translated by the author. The original responses are held in Ransomnews editorial records.
  • Trellix, “Read The Manual Locker: A Private RaaS Provider,” April 2023: trellix.com
  • Related reading on Ransomnews: what ransomware-as-a-service actually is, our analysis of database ransom economics, and the wider threat-group catalogue.

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleLive Stripe keys for 659 merchants, published for free
Next Article “Delve” is dead: AI writing tells expire in 18 months
Dancho Danchev
  • LinkedIn

Dancho Danchev is a Bulgarian threat intelligence researcher who has spent more than two decades tracking cybercrime, malware campaigns, and the infrastructure behind the criminal underground. His research covers botnets, including Koobface, exploit kits, blackhat SEO, scareware, and large-scale domain abuse, with a focus on OSINT work that maps campaigns back to the operators running them. He has published through ZDNet Zero Day, Webroot, GroupSense, and WhoisXML API, and has run his own cybercrime research blog since the early 2000s.

Comments are closed.

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,459 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.