Kovter is a Windows malware family best known for click-fraud operations and for its heavy use of fileless and living-off-the-land techniques. It became widely recognized for storing malicious code in the Windows Registry, using script interpreters and trusted system binaries to execute staged payloads, and injecting its final payload into legitimate processes. Kovter has been associated with large-scale malvertising and ad-fraud ecosystems, including operations linked to the 3ve botnet and the long-running KovCoreG campaign.
Kovter commonly persists through registry-based mechanisms that launch script content via native Windows components such as mshta and regsvr32. Observed variants use obfuscated JavaScript and PowerShell stages, shellcode loaders, reflective loading techniques, and process injection, including thread hijacking, to decrypt and execute payloads directly from registry-stored data. This architecture reduces reliance on conventional files on disk and complicates static detection and forensic recovery. Registry value hiding tricks and anti-analysis behavior have also been documented.
Its primary monetization role has been click fraud: infected systems generate fraudulent advertisement clicks or otherwise support ad-traffic abuse. In some campaigns, Kovter-related infrastructure and malware behavior evolved beyond simple ad fraud. Operators have been observed reprogramming infections after initial compromise, adding domain generation algorithm-based command and control, stronger persistence through DLL side-loading, and reconnaissance functions such as network and database scanning. These cases indicate that Kovter infections could serve as a foothold for broader post-compromise activity or for resale of access to other criminal actors.
Kovter has been delivered through multiple channels over time. High-confidence reporting links it to malvertising and exploit-kit activity, and it has also appeared as a secondary payload downloaded by other malware families and botnets. Fake software-update lures, especially bogus Adobe Flash updates, have been associated with campaigns that historically used Kovter or successor tooling. Kovter has also been observed as an additional payload delivered by other malware ecosystems.
The malware has been tied to financially motivated cybercrime rather than destructive or espionage-focused operations. Its operational history shows overlap with broader ad-fraud and traffic-manipulation campaigns that abused large numbers of infected consumer and enterprise Windows systems. Although primarily known as click-fraud malware, Kovter’s modular, stealthy, and fileless tradecraft made it notable as a flexible platform for persistence, evasion, and follow-on malicious activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
KovCoreG, active since 2011, is a long-running campaign known for using the Kovter botnet malware, which was distributed mainly through malvertisements and exploit kits.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
We've got a very obfuscated Javascript code that contains a big blob of binary data that deobfuscated and being sent to "eval" function which executes it
Bots were able to mimic desktop and mobile traffic in order to evade detection
This main Kovter payload responsible for injecting itslef to Regsvr32.exe, which injects itself to another instance of Regsvr32.exe.
Kovter uses Thread Hijacking technique to injects itself
creates a Powershell variable and initialize it with Powershell code that decodes a big blob of base64 and executes it
The command reads the registry value in HKCU\software\vmwbcodxx\eznyhwwfez and runs it as Javascript by Mshta.exe
A huge ammount of connections are made to variety of destinations by Regsvr32.exe
It uses a long list of IP's and URL's: The first 2 lines contain the C2 address
Sathurbot can update itself and download and start other executables. We have seen variations of Boaxxe, Kovter and Fleercivet
Instead of communicating via a standard command and control network, the hackers had re-programmed the malware to communicate by using domain generation algorithms. DGAs are more difficult to detect and offer a superior, more advanced way for attackers to communicate with their tools.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Kovter is described as fileless malware that uses encoded scripts stored in the registry for persistence and execution without relying on files.
Fileless malware referenced in relation to registry payload injection and persistence techniques.
Malware family/operation associated with malvertising and online fraud; described here as embracing social-engineering-driven schemes in recent years.
Earlier ransomware family mentioned for comparison with CryptoLocker.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.