Malware Kovter lives exclusively in the Windows Registry – Half of the users infected by Kovter live in America.
Symantec researchers have discovered a new variant of the Konter trojan, which mimics the Poweliks malware and is able to 'live' in the computer Registry, without necessarily being stored on the hard drive. Konter, which was first detected in 2013, is one of the most updated malware families, constantly changing its MO, adapting itself appropriately to new hacking campaigns and the security measures taken to stop it.
According to Symantec, starting with version 2.0.3 of the Konter malware, first detected in May 2015, the trojan borrowed 'survival' methods from Roweliks and can hide itself in the PC registry.
The registry is a special feature of Windows, a database about user profiles, settings, software, and hardware, that the Windows operating system uses on a regular basis. By storing its code in the registry, the Trojan remains longer on infected machines and serves as an entry point for other, more serious infections.
While in the past, Konter was known to be distributed hand-in-hand with ransomware, Symantec now reports that its 'deadly' form, Konter, focuses solely on click-fraud. Attackers are distributing the new version of Konter primarily through malvertising campaigns and attachments in spam emails.
In the most recent malware attack, Symantec reports that it has infected approximately 56% of the US, 13% of the UK, Canada (9%), Germany (8%), and Australia (2%).


