Blog | G5 Cyber Security

Kovter Ad Fraud Trojan Now Shipping with Locky Ransomware

Kovter is a fileless trojan that stores itself in the Windows registry for persistence and antivirus evasion. The distributors behind Kovter have been experimenting with ransomware since as early as January 2016. The threat actors have evolved from using a fake file encryption threat to using a well known and effective ransomware family: Locky. In this post we will examine the history of the Kovter actors experimentation with ransomware and walk through a sample campaign that PhishMe Threat Intelligence Team captured.”]

Source: https://cofense.com/kovter-ad-fraud-trojan-now-shipping-locky-ransomware/

Exit mobile version