The Redaman banking malware was first observed in the threat landscape in 2015, most of the victims were customers of Russian financial institutions. The malware was initially reported as the RTM banking Trojan, both Symantec and Microsoft detected Redaman in 2017 and classified it as a variant of RTM. The top 5 senders were Russia (3,845 sessions), Belarus (98), Ukraine (93), Estonia (29), and Germany (30), while the top 5 recipients are Russia (2,894), Netherlands (195), United States (55), Japan (16)”]
Source: https://securityaffairs.co/wordpress/80252/malware/redaman-banking-trojan.html

