Nodersok, also known as Novter and Divergent, is a modular fileless Windows botnet and backdoor associated with the KovCoreG malvertising operation. It was distributed through fake Adobe Flash update lures delivered via malvertising, which led victims to execute a malicious HTA application. The infection chain retrieved encrypted scripts, launched PowerShell, bypassed User Account Control through the CMSTPLUA COM interface, disabled Windows Defender and Windows Update components, and reflectively injected the malware into memory to minimize on-disk artifacts.
The malware performs anti-analysis and anti-debugging checks, including inspection for blacklisted processes and modules, debugger presence, manipulated sleep behavior, and low-resource environments. It establishes persistence by using HTA- and registry-based PowerShell components together with autorun mechanisms, enabling the infection to remain largely fileless after reboot. Nodersok communicates with multiple command-and-control channels for heartbeat traffic, configuration retrieval, and command execution, and supports commands to stop, resume, terminate, update, and load modules.
A notable characteristic is its modular architecture. Observed modules include a technical-support-scam component, a traffic-interference component that uses WinDivert to block or divert communications from selected security-related processes, and a Node.js-based proxy component known as Nodster. Nodster installs prerequisites as needed, manipulates network settings, and turns infected hosts into SOCKS-like proxies capable of handling multiple simultaneous TCP connections. Analysis of proxied traffic linked this infrastructure to ad-fraud activity, with attacker-generated traffic disguised as Android mobile application traffic. The malware primarily targets Windows systems and has been observed in campaigns initially focused on users in the United States before expanding into parts of Europe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Analysis of the Novter malware. Novter is a backdoor in the form of an executable file... The PowerShell script is also embedded with Novter, which will be executed filelessly via the PowerShell Reflective Injection technique.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
When the victim executes the HTA file, it will load additional scripts from a remote server (communication is RC4-encrypted) and run a PowerShell script
Novter communicates with its command-and-control (C&C) servers and downloads multiple JavaScript modules for different purposes.
KovCoreG’s attacks are socially engineered malvertisments that lure unwitting users into downloading a software package needed to update their supposedly out-of-date Adobe Flash application. However, it instead drops a malicious HTML application (HTA) file named Player{timestamp}.hta . When the victim executes the HTA file...
The attacker disguised the traffic to appear as if it was being sent from Android devices and mobile applications and proxied them through the Novter/Nodster botnet.
killall — Terminate a process and delete a file ... kill — Terminate a process and delete a file
However, it instead drops a malicious HTML application (HTA) file named Player{timestamp}.hta . When the victim executes the HTA file, it will load additional scripts from a remote server...
Immediately after its execution,it performs the following anti-debugging and anti-analysis checks: Searching for blacklisted processes and modules... Checking if the number of cores is too small
After the affected machine’s environment is double-checked and reported, the malware goes to sleep for a long time.
Immediately after its execution,it performs the following anti-debugging and anti-analysis checks: Searching for blacklisted processes and modules... Checking if the number of cores is too small
Novter communicates with its command-and-control (C&C) servers and downloads multiple JavaScript modules for different purposes.
One of them, which we named “Nodster,” is a network proxy module... This turns the system infected with Novter become a proxy for the attacker to use.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an example of malware known to use Windows Defender bypass techniques.
A modular fileless botnet/backdoor distributed via KovCoreG malvertising. It is delivered through a fake Adobe Flash update chain, executed filelessly via PowerShell reflective injection, performs anti-debugging and anti-analysis checks, communicates with multiple C2 servers, and can download and run additional modules including technical-support-scam, traffic-blocking, and proxy components to support click-fraud operations.
Fileless-capable backdoor/botnet malware delivered via the KovCoreG malvertising chain. It performs anti-analysis checks, disables Windows Defender and Windows Update-related processes, establishes persistence through HTA files and registry-stored PowerShell payloads, beacons to multiple C2 servers, downloads modules, executes commands, and updates itself.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.