PteroEffigy is a Gamaredon (also known as Shuckworm/Armageddon) PowerShell-based lightweight downloader observed in 2025 operations targeting Ukrainian government, military, and defense-related entities. It is one of six new PowerShell tools added to Gamaredon’s arsenal and is described as a simple downloader used to fetch next-stage payloads, additional malware, or command-and-control information. Its notable characteristic is abuse of the GoFile cloud storage service as a dead-drop mechanism to obtain the next C2 server. ESET also reported a chain in which PteroOdd dropped PteroEffigy, which then contacted the domain eset.ydns[.]eu to deliver Turla’s Kazuar v2, and PteroEffigy was observed on machines co-compromised by Gamaredon and Turla where Turla deployed Kazuar v3. High-confidence associations in the reporting tie PteroEffigy to Gamaredon’s sustained 2025 cyberespionage activity against Ukraine and to incidents reflecting operational collaboration or shared access with Turla.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Six new PowerShell tools, including PteroDee, PteroCache, PteroDum, PteroOdd, PteroEffigy, and PteroPaste, were introduced, broadening their custom malware capabilities.
...PteroOdd was used to drop another PowerShell downloader codenamed PteroEffigy, which ultimately contacted the "eset.ydns[.]eu" domain to deliver Kazuar v2...
8 distinct techniques documented for this family, organized by ATT&CK tactic.
...use of a wide range of legitimate services as data exfiltration channels and dead drop resolvers... hidden behind tunnels or serverless workers.
They also abused multiple legitimate messaging, social media, blogging, and paste services as dead drops for resolving C&C servers and distributing payloads.
Gamaredon abused multiple legitimate messaging, social media, blogging, and paste services as dead drops for resolving C&C servers... In 2025, Gamaredon abused numerous services in this way: Telegram channels, Telegra.ph, Teletype, rentry.co, write.as, Dropbox, GoFile, DEV Community, Mastodon, lesma, nopaste.net, and Paste.ee.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
One of six newly introduced Gamaredon PowerShell tools expanding the group's malware arsenal.
A new Gamaredon tool used to retrieve command-and-control server details via the GoFile cloud storage service.
A lightweight downloader used to fetch next-stage payloads, command-and-control information, or additional malware.
A lightweight downloader that uses the GoFile cloud storage service to obtain the next command-and-control server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.