Kovter

Malware type
ransomware
Family
Malware family
Last IoC activity
2026-04-11 00:20:59
Profile updated
2026-07-07 13:44:33

Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector retail-and-hospitality

Context

Kovter is a fileless malware family initially identified as ransomware. It later evolved into a click-fraud Trojan and is known for its anti-forensic techniques, making it difficult to detect and remove.

Detection coverage

  • 1 YARA rules

Detection rules

  • CAPE_Kovter (yara-rule)

Reports & references

  • CISA — Aa20 345A (report)
  • McAfee — Evolution Of Malware Sandbox Evasion Tactics A Retrospective Study (report)
  • McAfee — Evolution Of Malware Sandbox Evasion Tactics A Retrospective Study (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Kovter (report)
  • 0x00sec.org — 18663 (report)
  • github.com — Kovter.Md (report)
  • Broadcom/Symantec — Kovter Malware Learns Poweliks Persistent Fileless Registry Update (report)
  • blog.malwarebytes.com — Major Malvertising Campaign Hits Sites With Combined Total Monthly Traffic Of 1 5Bn Visitors (report)
  • Trend Micro — Kovter An Evolving Malware Gone Fileless (report)
  • github.com — Kovterwhitepaper (report)
  • cybereason.com — How Click Fraud Commodity Malware Transforms Into An Advanced Threat (report)
  • 0xchrollo.github.io — Unpacking Kovter Malware (report)
  • ry0dan.github.io — Unpacking Kovter Malware (report)
  • blog.malwarebytes.com — Untangling Kovter (report)

External references