Symantec researchers have discovered a new version of the Kovter trojan. The “mutated” version mimics the Poweliks malware and is able to reside in your computer’s registry, without needing to be stored on your hard drive.
Kovter, first spotted in 2013, has been one of the most advanced malware. Since then, its MO has been constantly changing, adapting to new hacking campaigns and security measures implemented to stop it.
According to Symantec, starting with version 2.0.3 of the Kovter malware (this particular version was first detected in the wild in 2015), the malware began borrowing survival methods from Poweliks. This allows it to hide in the computer registry.
The Windows registry is a special feature, a database containing information about the user profile, settings for software and hardware, which the Windows operating system uses on a regular basis.
By storing itself in the registry, Kovter hides very well on infected machines and serves as an entry point for other, more serious infections.
Symantec reports that attackers are distributing this new version of Kovter primarily through file attachments distributed in spam emails.
Symantec also reports that the malware has primarily infected users in the US (56%), the UK (13%), Germany (8%), and Australia (2%).
“The Кovter malware has been evolving continuously since it was first discovered and shows no signs of leaving the scene anytime soon,”
Symantec researchers report.
Symantec, however, developed and distributes a Trojan.Kotver removal tool for free.
You can download it from the link below.
