Morte Loader is a Loader-as-a-Service (LaaS) platform used to compromise SOHO routers, IoT devices, and public-facing web applications and convert them into flexible botnet infrastructure. It is described as not being tied to a single payload family; instead, affiliates can use it to deliver payloads such as Mirai variants, RondoDoX, cryptominers, or backdoors depending on the value and characteristics of the compromised device. The operation follows a three-tier cybercrime model involving infrastructure operators, botnet customers, and end users.
Initial access is achieved through exploitation of known vulnerabilities, use of default credentials, and brute-force attacks. Reported exploited vulnerabilities include CVE-2019-17574, CVE-2019-16759, and CVE-2012-1823, with WebLogic bugs also mentioned. After compromise, Morte deploys a shell bootstrap script and multi-architecture loader that fingerprints the device, gathers telemetry such as MAC address, firmware, hostname, open ports, and hardware details, and downloads the appropriate binary for the target CPU architecture using tools such as wget, curl, or tftp. It establishes HTTP-based command-and-control communication.
The loader is reported to clean traces, remove temporary files and shell history, clear logs, add persistence via boot or logon paths, and kill rival botnets, miners, and tools to retain control. It scans locations such as /tmp, /var/tmp, /dev/shm, and /run for competing malware. Payload selection is based on factors including CPU, memory, bandwidth, and network position of the infected device. RondoDoX is identified as a main payload with modular DDoS capability using HTTP/2 and persistent connections.
Morte infrastructure is rotated frequently, with open directories and changing filenames and binaries used to evade detection. Reused URL patterns include http://<ip>/morte.<arch> and http://<ip>/bins/morte.<arch>. More than 800 public files have reportedly been linked to Morte, and many remain undetected by some security engines. The malware ecosystem supports DDoS, cryptomining, access resale, and further intrusion, effectively turning edge devices into shared rentable infrastructure for cybercrime.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Morte Loader is a Loader-as-a-Service (LaaS) malware that compromises SOHO routers, IoT devices, and web applications to build multi-purpose botnets. It is rented by other threat actors to deliver various payloads, including Mirai, RondoDoX, cryptominers, and backdoors. Morte establishes persistence, cleans traces, fingerprints devices, and kills rival malware, enabling affiliates to deploy their own modules for DDoS, cryptomining, or access resale.
Morte Loader is a Loader-as-a-Service (LaaS) malware that compromises SOHO routers, IoT devices, and web applications to build multi-purpose botnets. It is rented by other threat actors to deliver various payloads, including Mirai, RondoDoX, cryptominers, and backdoors. Morte Loader establishes persistence, cleans traces, fingerprints devices, and enables affiliates to deploy additional malware based on device value.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.