Kovter is a malware family and criminal activity cluster historically associated with malvertising-driven infections, click-fraud, and fileless persistence techniques. It has been used to deliver or support financially motivated cybercrime operations, often relying on social engineering and deceptive advertising chains to reach victims. Kovter became notable for registry-based persistence and stealthy execution methods that reduced on-disk artifacts, as well as for operating through malvertising and traffic-redirect ecosystems. Public reporting has at times discussed possible overlaps between Kovter-related landing pages and other malvertising operations, but at least one such suggested linkage to Zirconium was later explicitly withdrawn for lack of evidence. High-confidence attribution in this context therefore supports Kovter as a financially motivated cybercrime actor or malware operation associated with malvertising, but does not support a confirmed relationship with Zirconium.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.