PULSE NAME
Inside Morte Loader: How Loader as a Service Builds Modern Botnets
WHITE PetrP.73 2025-12-01 Modified: 2025-12-31
81
IOCs
HIGH VOLUME
Morte is a Loader as a Service (LaaS) designed to exploit vulnerable Small Office/Home Office (SOHO) routers, IoT devices, and web applications, effectively transforming these often-overlooked assets into a multifaceted botnet platform. Rather than deploying a specific malware strain, Morte provides a versatile loader that can be rented by cybercriminals to deliver various payloads such as Mirai, RondoDoX, cryptominers, or backdoors, adapting its approach based on the value associated with each compromised device. The initial access process employs various techniques, including leveraging known CVEs, exploiting default credentials, and conducting brute force attacks against the web management panels of devices. This initial compromise is facilitated by a small shell bootstrap script that fingerprints the device's characteristics, subsequently downloading the appropriate Morte binary compatible with its CPU architecture.
Indicators of Compromise (24 / 81 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 CVE
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 6feaaf0ac98e5388e98c518e7c27ea77 MD5 of b8e0f37a4b4647f17da3fa0b9fec59858517be7a410b220f3892864a05d6abb9 2025-12-01
FileHash-MD5 93a5f087af1d8e2d0ee50ce8898a92e0 MD5 of fe9608ecb6c6f60cce0eef72f1aedf2946b08b38ac5259f703b220abb644ea33 2025-12-01
FileHash-MD5 c1ac1d1533896043e3e02962817bdff5 MD5 of 16ba16bf6f0d4de4341bf38820777755012f008554f5e482b88cd4a85e97eb8b 2025-12-01
FileHash-MD5 04dbcaf16b0c7e7bf92a85d6916241aa MD5 of 54f074f9741c2480533ce774637dae79d011ba9bc616e1215ad9ddf488e162f6 2025-12-01
FileHash-MD5 55a2a6b6527bc9e6e6906aedc09c3058 MD5 of 9ee5066a1854ee15278b55e0a4cf9c58c2446f0f4599d1de85202c2341026bbb 2025-12-01
FileHash-MD5 73a27b58a37092d78e7c26a5dea6bfd1 MD5 of c2a281ca005af49c10f80f10ce0d2b874015e794bf023e78111206cd68f5f183 2025-12-01
FileHash-MD5 89aed0f991aa5aa592d0d3437ac60aff MD5 of d6b4631589c6c68093f7d1efe718696be4c7b48684c47c515b4845ea6111a3b7 2025-12-01
FileHash-MD5 d89bf59edef54535a4ba5efd1204f894 MD5 of 9b25b603427438fe93e5a6851c94cf877f4279dd093882c8e02189aa195d9d31 2025-12-01
FileHash-MD5 e7e6da4866a3885cde826e7bbe122006 MD5 of 7df91ed3adb982a228a860e2e68a504e42b6a092b16889b14abd09702257fea6 2025-12-01
FileHash-MD5 f66e259d2a2669717f1bce173e535a8d MD5 of 3bf970fac214de8ac4440e7ea7938d15dfe9db8c3a63807e58a74a6510aa05f3 2025-12-01
FileHash-MD5 02544147db4a306df75e581687cd50b9 MD5 of eb3c93a6f4ff83533c2c255ae54a27cc810cc8e0e7462f4c304f53c47a90bbba 2025-12-01
FileHash-MD5 34f42f00d159023eacc804617d772e41 MD5 of 3f8dea0daa29a990427b45142d285b3f587dee4955255b0c16f88181d8eeb8a5 2025-12-01
FileHash-MD5 5ad376cb4f8cbcd0c706ff0296792ce8 MD5 of e9d5b1831ec251f9ed3b236c8e6cae7b1a702475270aa88a89bf75f8331b5754 2025-12-01
FileHash-MD5 7f31c47ae746b95f5ed225a2325bc2cc MD5 of 8a2880ab70300e517b82d6aebb562ea7c0d6b9c1214484a59d6c2a186d77ffc7 2025-12-01
FileHash-MD5 91525cd9d85540e423902227ab5534d2 MD5 of f88aa064da17427cee044401a23918bb616950b2a1c9efb2bea5be89265aa0c6 2025-12-01
FileHash-MD5 a345586c6df2b032e5a3d309f9d5e5c9 MD5 of 6d7f5dcbbdda3ae9840e08937f02daa2a7f1546777684c4336b10a1fe31ca50c 2025-12-01
FileHash-MD5 e900f815668a173e9ef34f9a88592ff5 MD5 of cf06e258e721169d18401a20085bd449c39dacea2b2da351703394f83a604d5e 2025-12-01
FileHash-MD5 63e1499643ca9e24b4e83dc923bfb474 MD5 of 664479fec42ed9949bbe153e67bd8618fb4be3dba9d1cf8688eb6faa6e2fad34 2025-12-01
FileHash-MD5 69d253dda1458edc3b826079ee116093 MD5 of e55ee7ca95beca998c6bc5f728ec0c2d1fa8af88a3bc54c2a61c7ad3df1a1eaa 2025-12-01
FileHash-MD5 8a3c2c8b4c902c99d8a43f461c8602b0 MD5 of 426cfa343d2637ae555e921aebea6a66f5370011e06dff0110d6bb73b17f3920 2025-12-01
FileHash-MD5 b11bcb64aadaf9ad2e2573abdd43b25d MD5 of 20eec1f49d7ab9223b5d47b6f464aed12e418942570966eae401968088463f1a 2025-12-01
FileHash-MD5 be4a16f1e8a06dccb243caf57d2be1b4 MD5 of 3a1845d8f359309f6583dbc015338b1142da2c7217dfeef9cc6a1d557b9b4663 2025-12-01
FileHash-MD5 c69c3692890c281dd44aceedeb85d613 MD5 of e9adfb0ec60476cbc147d52828c722770deed9bc4ac8d0f9a91cdb5c54926ecc 2025-12-01
FileHash-MD5 ee1f57fecfde4a1ed526535a87aa957d MD5 of 319bcb9236451105db1e4b0f71160d10066bb569b378a3fbe95b0fc2028f22c1 2025-12-01