New Worm Preys On Weak & Helpless Passwords For Windows Remote Desktop [News]

Say hello to Morto, a Windows worm that has been spreading like wildfire over the last weekend. This new nasty has struck by spreading over the Windows Remote Desktop Protocol. Rather than using fancy network trickery, Morto attempts to infect its target by entering passwords commonly used to secure RDP.

Like many previous worms, this new threat is not technically sophisticated but remains effective due to its persistence. While only a small number of systems may be accessible with the passwords that Morto tries, the worm uses every infected machine to scan for additional targets and spreads itself relentlessly. One infection on a network can quickly turn into a full-blown PC plague. Infected machines also have their security software discreetly terminated, making the worm more difficult to find and remove.

Security researchers caught the worm when they noticed spikes in network traffic, specifically traffic related to TCP port 3389, which is the port Windows Remote Desktop monitors for access requests. While the worm has caused a general increase in Internet traffic, the impact has so far been minimal. The worm does not seem to contain a damaging payload, so researchers do not yet know the method behind the madness.

Protection against Morto is simple. Disabling Windows Remote Desktop will cut off its means of infection. Alternatively, a strong password containing random letters and numbers can thwart the worm.

Source: Computer World

Did you find this useful? Share it with others

Matt Smith

Matthew Smith is a freelance writer living in Portland Oregon. He runs the blog Smidgen PC and writes for Digital Trends and PC Perspective in addition to Makeuseof.

Similar Stuff

The comments were closed because the article is more than 180 days old.

If you have any questions related to stuff mentioned in the article or need help with any computer issue, just ask it on MakeUseOf Answers.

Hide 4 Comments

  • No August 30, 2011

    So how do you disable the remote desktop ?
    woot.

    • Matt Smith August 31, 2011

      Go to System Properties in the Windows Control Panel, go to the Remote tab, then un-check the Allow Remote Assistance box.

  • ekaspar August 30, 2011

    This is really discouraging when you find an article where the TITLE is misspelled. Try “PREYS on weak and helpless passwords”.
    Come on guys.

  • eBridge advertising August 30, 2011

    A new worm called Morto has begun making the rounds on the Internet, infecting machines via Remote Desktop Protocol. …thanks for the post!