Pteranodon, also tracked as Pterodo, is a long-running custom Windows backdoor and deployment framework associated with the Russia-linked Gamaredon threat actor, also known as Armageddon, Shuckworm, ACTINIUM, and UAC-0010. It has been used extensively in cyber-espionage operations primarily targeting Ukrainian government, military, security, and other state-linked organizations, with reporting indicating development and operational use over many years.
Pteranodon functions as a modular backdoor used to maintain access on compromised systems, execute arbitrary commands, load additional payloads, and support follow-on collection activity. Documented capabilities include periodic screenshot capture and exfiltration of those screenshots to command-and-control infrastructure, theft and exfiltration of files from local systems and removable media, and execution of additional code and scripts. Variants and related components have been observed using Visual Basic Script heavily, including VBS droppers and staged script execution, and leveraging trusted Windows binaries such as mshta.exe and rundll32.exe for execution.
Persistence mechanisms associated with Pteranodon include scheduled tasks and copying components into the Windows Startup folder. Reported behavior also includes cleanup and anti-forensic actions such as deleting temporary files, removing files that interfere with execution, and self-deletion after initial script execution. In broader Gamaredon intrusion chains, Pteranodon has commonly appeared after spearphishing-based initial compromise involving malicious Office documents, macro-enabled templates, or other script-based launchers, and in some cases has also been propagated via USB-related mechanisms.
Operationally, Pteranodon has been a core element of Gamaredon’s espionage toolkit and later evolved into multiple related or variant payloads deployed simultaneously on victim systems to improve resilience and persistence. Its role in sustained access, surveillance, payload delivery, and data theft makes it a central component of Gamaredon’s long-running campaigns against Ukrainian targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Документи ... містили шкідливий код для експлуатації відомої вразливості «Microsoft Office» CVE-2017-0199 ... що надає змогу зловмиснику виконати довільний код на пристрої користувача, при відкритті інфікованого файлу.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Gamaredon’s infection chain: Spoofed emails, GammaDrop and GammaLoad ... Inside Gamaredon’s PteroLNK ... ACTINIUM targets Ukrainian organizations Pteranodon ... Renewal of cyber attacks using the Pterodo hacker group Armageddon/Gamaredon
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Next, the script enumerates all drives, copying itself to any available removable disks – USB drives. These USB drives are likely used by the attackers for lateral movement across victim networks and may be used to help the attackers reach air-gapped machines within targeted organizations.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
After the document was opened, a malicious PowerShell command was observed being executed to download the next-stage payload... Next, a VBS script, which was Shuckworm’s Pterodo backdoor, was executed.
After the document was opened, a malicious PowerShell command was observed being executed to download the next-stage payload from the attackers’ C&C server... Shuckworm has also been observed using a new PowerShell script in order to spread its custom backdoor malware, Pterodo, via USB.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
APT-C-36 has embedded a VBScript within a malicious Word document which is executed upon the document opening.
The remaining lines of code end up writing a VBScript file and placing it in the user’s startup directory.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The first registry modification made by this macro changes the key value of AccessVBOM to 1... The second registry modification enables all macros automatically and disables warnings for future macro-enabled objects.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The new PowerShell script is used to first copy itself onto the infected machine and create a shortcut file using an rtk.lnk extension. The script uses file names such as “porn_video.rtf.lnk”, “do_not_delete.rtf.lnk” and “evidence.rtf.lnk” in an attempt to entice individuals to open the files.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The new PowerShell script is used to first copy itself onto the infected machine and create a shortcut file using an rtk.lnk extension. The script uses file names such as “porn_video.rtf.lnk”, “do_not_delete.rtf.lnk” and “evidence.rtf.lnk” in an attempt to entice individuals to open the files.
The macro code was obfuscated using string concatenation and procedurally generated variables — techniques that are often used to bypass static detection technologies.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
APT29 has use mshta to execute malicious scripts on a compromised host... APT32 has used mshta.exe for code execution... APT38 has used a renamed version of mshta.exe to execute malicious HTML files... FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
Next, the script enumerates all drives, copying itself to any available removable disks – USB drives. These USB drives are likely used by the attackers for lateral movement across victim networks and may be used to help the attackers reach air-gapped machines within targeted organizations.
In this recent activity, we also observed the group leveraging legitimate services to act as C&C servers, including using the Telegram messaging service for its C&C infrastructure. More recently, they have also used Telegram’s micro-blogging platform, called Telegraph, to store C&C addresses.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
Inside Gamaredon’s PteroLNK: Dead Drop Resolvers and evasive Infrastructure
Gamaredon’s infection chain: Spoofed emails, GammaDrop and GammaLoad
183 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
56 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware framework previously used by Gamaredon before its tooling evolved into more fragmented modular malware families.
A custom-built framework previously used by Gamaredon before its tooling evolved into more fragmented and modular malware variants.
A historical custom backdoor and deployment framework used by Gamaredon. It loaded additional payloads, executed arbitrary commands, captured screenshots, and stole files from local systems and USB drives for exfiltration.
Backdoor associated with UAC-0010 (Gamaredon).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.