Kovter
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-04-11 00:20:59
- Profile updated
- 2026-07-07 13:44:33
Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector retail-and-hospitality
Context
Kovter is a fileless malware family initially identified as ransomware. It later evolved into a click-fraud Trojan and is known for its anti-forensic techniques, making it difficult to detect and remove.
Detection coverage
- 1 YARA rules
Detection rules
- CAPE_Kovter (yara-rule)
Reports & references
- CISA — Aa20 345A (report)
- McAfee — Evolution Of Malware Sandbox Evasion Tactics A Retrospective Study (report)
- McAfee — Evolution Of Malware Sandbox Evasion Tactics A Retrospective Study (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Kovter (report)
- 0x00sec.org — 18663 (report)
- github.com — Kovter.Md (report)
- Broadcom/Symantec — Kovter Malware Learns Poweliks Persistent Fileless Registry Update (report)
- blog.malwarebytes.com — Major Malvertising Campaign Hits Sites With Combined Total Monthly Traffic Of 1 5Bn Visitors (report)
- Trend Micro — Kovter An Evolving Malware Gone Fileless (report)
- github.com — Kovterwhitepaper (report)
- cybereason.com — How Click Fraud Commodity Malware Transforms Into An Advanced Threat (report)
- 0xchrollo.github.io — Unpacking Kovter Malware (report)
- ry0dan.github.io — Unpacking Kovter Malware (report)
- blog.malwarebytes.com — Untangling Kovter (report)