Morto

First seen
2011-08-15 00:00:00
Malware type
worm
Profile updated
2026-07-07 15:12:37

Context

Morto is a network worm that spreads by exploiting weak passwords in the Windows Remote Desktop Protocol. It is known for quickly spreading over networks by brute-forcing RDP credentials.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Morto_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Morto (report)
  • contagiodump.blogspot.com — Aug 28 Morto Tsclient Rdp Worm With (report)
  • f-secure.com — 00002227 (report)
  • Microsoft — Malware Encyclopedia Description (report)

External references