Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 18:06:36 UTC Home > List all groups > List all tools > List all groups using tool RMS Tool: RMS Names RMS Remote Manipulator System Gussdoor RuRAT Category Tools Type Backdoor, Info stealer Description CyberInt states that Remote Manipulator System (RMS) is a legitimate tool developed by Russian organization TektonIT and has been observed in campaigns conducted by TA505 as well as numerous smaller campaigns likely attributable to other, disparate, threat actors. In addition to the availability of commercial licenses, the tool is free for non-commercial use and supports the remote administration of both Microsoft Windows and Android devices. Information Malpedia Last change to this tool card: 30 November 2023 Download this tool card in JSON format All groups using tool RMS Changed Name Country Observed APT groups Gamaredon Group 2013-Feb 2025 LazyScripter [Unknown] 2018 TA505, Graceful Spider, Gold Evergreen 2006-Nov 2022 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6b263aa0-475c-413f-b618-ed55c6546690 Page 1 of 2 3 groups listed (3 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6b263aa0-475c-413f-b618-ed55c6546690 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6b263aa0-475c-413f-b618-ed55c6546690 Page 2 of 2