{
  "family": "kovter",
  "sample_count": 2414,
  "category": "click_fraud",
  "description": "Kovter is a malware family targeting Windows that, per Malwarebytes, has 'many faces' — its main variants are aimed at ad/click fraud and are hard to detect and remove because they use fileless infection methods. It usually arrives as a macro in a Word document email attachment; when the macro runs, it downloads a file that creates a PowerShell command stored in the Windows registry to gain persistence, after which the dropped file deletes itself. Over its history Kovter evolved through police-themed ransomware and downloader roles before becoming known for click fraud.",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Kovter"
  ],
  "enrichment_level": "curated_sourced",
  "faq": [
    {
      "@type": "Question",
      "name": "What is Kovter?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "A Windows malware family best known for ad/click fraud, notable for using fileless techniques that make it hard to detect and remove."
      }
    },
    {
      "@type": "Question",
      "name": "Why is Kovter called 'fileless'?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "It stores its persistence mechanism as a PowerShell command in the Windows registry rather than as an ordinary file, and the dropped file deletes itself, leaving little on disk."
      }
    },
    {
      "@type": "Question",
      "name": "How does Kovter infect a machine?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "It usually arrives as a macro inside a Word document email attachment; running the macro downloads and sets up the malware."
      }
    },
    {
      "@type": "Question",
      "name": "What does Kovter do?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Its main variants perform ad/click fraud; over time it has also been associated with ransomware and downloader behavior."
      }
    },
    {
      "@type": "Question",
      "name": "How can I protect against Kovter?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Disable Office macros from untrusted documents, be cautious with email attachments, and use reputable security software."
      }
    },
    {
      "@type": "Question",
      "name": "Where can I read an authoritative source on Kovter?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Malwarebytes maintains a Trojan.Kovter detection page, linked on this page."
      }
    }
  ],
  "faq_count": 6,
  "mitre_attack": [
    "T1112",
    "T1059.001",
    "T1027.011",
    "T1547.001",
    "T1055"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-06-09",
  "sources": [
    {
      "name": "Malwarebytes: Trojan.Kovter",
      "url": "https://www.malwarebytes.com/blog/detections/trojan-kovter"
    }
  ],
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}