The Morto (Worm:Win32/Morto.A) malware spread by brute-forcing administrator credentials over Remote Desktop Protocol on port 3389, allowing it to move laterally across Windows systems on the same subnet. After gaining access, it installed a malicious clb.dll in the Windows directory, abused DLL search order hijacking through regedit and service DLL loading, stored encrypted code under HKLM\SYSTEM\WPA, and imported registry changes designed to weaken UAC protections and force rundll32.exe to run with elevated privileges.
Analysis of samples showed the worm contacting domains including jifr.info, jifr.co.cc, jifr.co.be, qfsl.net, qfsl.co.cc, and qfsl.co.be, as well as IP addresses such as 210.3.38.82 and 111.68.13.250, to retrieve additional components including a file identified as 160.rar. The malware created temporary executables in C:\WINDOWS\Temp using the ~MTMP####.exe pattern, performed DNS lookups through numerous external resolvers, terminated security-related processes, cleared Windows event logs, and could be instructed to launch denial-of-service attacks against attacker-selected targets.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
The analysis recorded qfsl.net resolving to 111.68.13.250 in Hong Kong and stated that this infrastructure issued orders for a DDoS test, with observed traffic to Google infrastructure returning HTTP 400 errors.
An analysis of a Morto/Tsclient sample described its dropped clb.dll payload, use of external DNS resolvers, contact with jifr and qfsl infrastructure, and retrieval of additional components including 160.rar from 210.3.38.82.
Microsoft documented Worm:Win32/Morto.A as an RDP-brute-forcing worm that installs clb.dll, spreads laterally over TCP 3389, downloads updated components, and can perform attacker-directed denial-of-service attacks.
A DLL analyzed as part of the Morto malware chain carried a PE compile timestamp indicating it was built on 2011-08-23 08:34:14.
The domain jifr.net, later associated with Morto infrastructure, was registered through Jiangsu Bangning Science & Technology Co. Ltd.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 37 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.