HomeSecurityKovter click-fraud malware evolves into ransomware

Kovter click-fraud malware evolves into ransomware

Security researchers from Check Point report a change in the way the Kovter malware operates, which has slowly transformed into a weak crypto-ransomware variant.

Kovter began in 2013 as a simple ransomware variant that locked people's computers and displayed a message asking them to pay a fine or face legal action. In most cases, this message was posted using insignia and graphics specific to local law enforcement, depending on the user's country of origin.

Kovter click-fraud malware evolves into ransomware

As these types of ransomware campaigns began to become ineffective, starting in 2014, Kovter evolved and specialized in click-fraud activities, loading and clicking on ads without the user's knowledge.

This lasted for two years, during which time the malware became famous for the rapid pace at which it evolved, always adding new features.

The peak of this never-ending update cycle was reached last fall, when Kovter became a fileless threat, living in the memory and Windows registry of the infected computer.

But as ransomware began to become a big business in recent months, the authors of Kovter, wanting to follow the trend, decided to evolve the Kovter codebase once again, going back to where it all began.

This new version of Kovter ransomware is nothing like the original because, instead of locking users' computers, Kovter now encrypts their files.

Fortunately, Check Point says that Kovter cannot yet be considered a worthy opponent of Locky or TeslaScrypt, and that its encryption can be defeated. As the researchers explained, Kovter does not encrypt all files, but only the first few bytes of each file and then stores the encryption key on disk. This decryption key can be discovered and used to unlock all encrypted files.

Unfortunately, Check Point has not released a decryptor for this ransomware, meaning there is no simple one-click solution to recover their files, and infected users may need the help of a professional to get their data back.

The strange thing about Kovter is that its creators seem to have focused more on avoiding detection by antivirus programs, rather than using a strong encryption algorithm. If a Kovter ransomware decrypter becomes available, we will update you with a new article.

UPDATE: Well, that was really quick. Lawrence Abrams from Bleeping Computer told Softpedia that a decrypter is already available, because the ransomware was previously detected under the name Nemucod.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS