Researchers linked Nodersok—also tracked as Novter and Divergent—to the long-running KovCoreG malvertising operation, which used fake Adobe Flash update lures and compromised ads on popular websites to infect Windows systems. The multi-stage chain abused legitimate tools including mshta.exe, PowerShell, node.exe, and WinDivert, fetched RC4-encrypted payloads from short-lived infrastructure and CDN services such as Cloudfront and Cdn77, and ran largely in memory using HTA execution, registry-based staging, and reflective PE injection. The malware also attempted to disable Windows Defender and Windows Update, bypassed UAC through CMSTPLUA, and established persistence through registry Run keys and scheduled tasks.
The final payload turned infected hosts into proxy zombies and click-fraud nodes, with Node.js-based modules supporting SOCKS4A relaying and fraudulent ad traffic disguised as Android or iOS devices through TCP/IP and SYN packet manipulation. Additional modules supported traffic blocking and technical-support scam activity, while anti-analysis checks and encrypted command-and-control updates helped the operators keep the campaign active and evolving. Microsoft said the operation hit thousands of systems, mostly consumer devices in the United States and Europe, with some enterprise victims across sectors including education, healthcare, finance, retail, and professional services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Trend Micro and Proofpoint researcher Kafeine identified Novter as a modular fileless botnet distributed by KovCoreG and concluded its Nodster module was used to proxy attacker-generated ad traffic disguised as Android mobile-app traffic. The report also noted the campaign had expanded from U.S. targets into several European countries.
Microsoft published technical details on the multi-stage fileless Nodersok campaign, describing its use of mshta.exe, PowerShell, node.exe, and WinDivert to turn infected systems into proxy zombies. Microsoft also said Defender ATP detected and disrupted the campaign through behavioral, memory, and command-line protections.
Cisco Talos published analysis of a previously undocumented malware family named Divergent and its loader. Talos described its registry-backed fileless installation, PowerShell reflective injection, anti-analysis checks, WinDivert abuse, and NodeJS-based click-fraud components.
Microsoft says it uncovered the Nodersok campaign in mid-July after detecting anomalous use of mshta.exe in Defender ATP telemetry. The campaign had targeted thousands of machines, mostly consumers in the United States and Europe.
Trend Micro says the KovCoreG campaign had been distributing the modular fileless botnet Novter, also known as Nodersok and Divergent, since March. The campaign used fake Adobe Flash update lures and malvertising to infect users.
Cisco Talos found the earliest reference containing several Divergent indicators of compromise dated back to February 2019. This shows the malware family was active by at least that month.
Trend Micro reports the Kovter botnet was taken down at the end of 2018 through efforts by law enforcement and cybersecurity experts, including Trend Micro. The operators then continued activity and developed another botnet.
Trend Micro says the Kovter botnet had been involved in click-fraud operations since 2015. This provides historical context for the later Novter/Nodersok activity tied to KovCoreG.
Trend Micro states the KovCoreG malvertising campaign has been active since 2011. It later became associated with Kovter distribution and click-fraud activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
trendmicro.com
Open sourceblog.trendmicro.com
Open sourceblog.talosintelligence.com
Open sourcemicrosoft.com
Open sourcedocuments.trendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.