Select your language

A new worm spreads on Remote Desktop Protocol (RDP) connections

F-Secure security researchers warn users about a new computer worm that tries to force Remote Desktop Protocol (RDP) connections.

RDP was developed by Microsoft to allow remote management of computers through a graphical interface. The technology is present, with limitations in some cases, in all supported versions of Windows.

According to F-Secure researchers, once a computer is infected,

... F-Secure security researchers warn users about a new computer worm that tries to force Remote Desktop Protocol (RDP) connections.

RDP was developed by Microsoft to allow remote management of computers through a graphical interface. The technology is present, with limitations in some cases, in all supported versions of Windows.

According to F-Secure researchers, once a computer is infected, the new Morto worm starts looking for machines that accept connections on TCP port 3389, default for RDP.

- Publicidad -

When potential targets are identified, the worm attempts to log on as an administrator with a list of encrypted passwords. This can lead to an uptick in RPD traffic on networks.

If authentication succeeds, Morto leaves its components on the destination computer, including the files %windows%\temp\ntshrui.dll and \windows\offline web pages\cache.txt.

The worm reports to a server by querying various predefined domain names and IP addresses from which other command and control files can be downloaded.

Morto's core functionality is to launch distributed denial-of-service (distributed DDoS) attacks. In addition, the application destroys processes that contain certain strings that match many popular security applications.

According to scans conducted by VirusTotal, 19 of the 44 antivirus engines currently using the service can detect the threat. It is recommended that users disable the RDP of their computers that do not need it or set a strong password for the Administrator account if they decide to keep it activated.

Some people may initially suspect that the worm may exploit an RDP vulnerability that was patched earlier this month (MS11-065) but this is not the case, as that flaw can only result in denial of service and not arbitrary code execution.

However, users should apply all available security patches for their operating system and should run an up-to-date antivirus program at all times.

- Publicidad -

Author: Lucian Constantin
Source: Softpedia

See original.

No comments

• If you're already registered, please log in first. Your email will not be published.

Comments are closed

The comments for this content are closed.

Investing in Access Controllers: Why Eliminating Them Can Be a Strategic Mistake

Investing in Access Controllers: Why Eliminating Them Can Be a Strategic Mistake

Thanks to technological evolution, today there are smart readers with the capacity to process credentials, store information and even operate locks autonomously. This has led many organizations to...

Case study: How did a retail chain in Costa Rica reduce fraud by 18%?

Case study: How did a retail chain in Costa Rica reduce fraud by 18%?

Almacenes El Rey is a rapidly expanding department store, with 18 branches nationwide and more than one million customers each year. Thanks to the Avigilon Unity Video solution, the retail chain...

Is storing video no longer enough? Milestone's Sales Director for Latam speaks

Is storing video no longer enough? Milestone's Sales Director for Latam speaks

Latin America. Johana Arias, an executive at Milestone Systems, discusses how the integration of AI, natural language, and open platforms are transforming video into actionable insights for...

Anti-intrusion system described as one of Ajax's largest in South America

Anti-intrusion system described as one of Ajax's largest in South America

Argentina. The Bayron company installed a protection system with more than 85 Ajax wireless devices in the new branch of Autos del Sur S.A., Toyota's official dealership in the country.

Interview with Manuel Carlos, Senior Sales Director for Mexico at Hanwha Vision

Interview with Manuel Carlos, Senior Sales Director for Mexico at Hanwha Vision

Mexico. Manuel Carlos, an executive at Hanwha Vision, details how the company is revolutionizing electronic security by consolidating generative artificial intelligence and processing at the edge.

Prosegur presents new capabilities in cybersecurity and automation

Prosegur presents new capabilities in cybersecurity and automation

International. Prosegur Security has created two new modules, xCope and xEcute, which aim to provide companies and organizations with a new corporate digital surveillance service and another for...

Access and video platform

Access and video platform

Johnson Controls Designed to take the complexity out of legacy systems, the latest version of C•CURE IQ helps organizations achieve faster response, simplify workflows, and turn safety data into...

SIA presents the new directives of its International Relations Committee

SIA presents the new directives of its International Relations Committee

Latin America. Mariana Ramírez is the new president of the International Relations Committee of the Security Industry Association (SIA), while Vanesa Cabral assumed the role of vice president.

Access management and security in stadiums during the World Cup

Access management and security in stadiums during the World Cup

International. With the World Cup underway, stadium operation and the management of credentials and critical assets become key factors in ensuring security in high-demand environments.

Jovicard modernizes its headquarters with HID access control technology

Jovicard modernizes its headquarters with HID access control technology

Brazil. Jovicard, which specializes in physical access control, secure identity, biometrics and integrated electronic security, completed the modernization of its corporate headquarters with trusted...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter