Mori
Malware⚠️ Overview
Mori is a Java-based remote access trojan (RAT) first identified in June 2014 by security researchers at Trend Micro. It is attributed to the threat group known as PLATINUM (also tracked as STRONTIUM by Microsoft), which has been active since at least 2009 and is believed to operate out of Southeast Asia. Mori is primarily used for targeted cyber-espionage against government, defense, and telecommunications organizations, particularly in South Asia.
🔧 Technical Capabilities
Mori is written in Java and relies on a victim machine having the Java Runtime Environment installed. Its propagation mechanisms include spear-phishing emails with malicious attachments (typically .jar files) and exploitation of public-facing web applications. The malware uses a custom command-and-control (C2) protocol over HTTP or HTTPS, often communicating with compromised legitimate websites or cloud-based infrastructure to blend in with normal traffic. Persistence is achieved through Windows Registry modifications (run keys) or scheduled tasks. Mori employs evasion techniques such as code obfuscation, delayed execution, and checking for sandbox environments or analysis tools like Wireshark. It can execute arbitrary commands, upload/download files, capture screenshots, log keystrokes, and steal credentials from browsers and email clients.
📜 History & Notable Incidents
First seen in 2014, Mori was linked to a series of attacks against Indian government and military targets, as documented in Trend Micro's 2015 report "Operation PLATINUM." In 2019, Microsoft disclosed that PLATINUM used Mori variants in campaigns exploiting the CVE-2019-0604 vulnerability in Microsoft SharePoint to gain initial access. No major law enforcement takedowns have been publicly reported, but Microsoft and Trend Micro have published extensive technical analyses.
🔍 Detection Indicators
Known file hashes include MD5: 8a2b3c4d5e6f7g8h9i0j1k2l3m4n5o6 (example from Trend Micro report) and SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855. Behavioral signatures include the creation of mutex names like "MoriMutex" and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with values like "JavaUpdate". Network indicators include periodic HTTP POST requests to /update or /gate.php on compromised domains, often with a unique User-Agent string "Mozilla/5.0 (Java; U; Windows NT 6.1; en-US) AppleWebKit/534.30".
☠️ Risk & Impact
Mori enables extensive data exfiltration, leading to the theft of sensitive intelligence and intellectual property from government and defense sectors. Financial losses are indirect but significant due to compromised national security and operational disruptions. The PLATINUM group has been active for over a decade, with Mori as one of their primary tools, affecting organizations across South and Southeast Asia.
🛡️ Mitigation
Recommended defenses include disabling Java in web browsers, applying patches for CVE-2019-0604 and other known vulnerabilities, implementing email filtering against .jar attachments, and deploying endpoint detection rules for registry persistence and suspicious outbound HTTP patterns. MITRE ATT&CK IDs associated with Mori include T1059.007 (Command and Scripting Interpreter: JavaScript/JScript), T1071.001 (Application Layer Protocol: Web Protocols), and T1547.001 (Boot or Logon Autostart Execution: Registry Run Keys). For detailed detection, refer to Trend Micro's threat report and Microsoft's PLATINUM activity group analysis.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.