PteroEffigy
PteroEffigy is a Gamaredon (aka Shuckworm/Armageddon/ACTINIUM) PowerShell-based lightweight downloader observed in 2025 operations targeting Ukrainian entities. ESET described it as one of several simple Ptero* downloaders used by Gamaredon to fetch next-stage payloads, command-and-control information, or additional malware. In reported Gamaredon-Turla co-compromises in Ukraine, PteroEffigy was deployed alongside other Gamaredon tools including PteroLNK, PteroStew, PteroOdd, and PteroGraphin, while Turla deployed the Kazuar backdoor. ESET also observed PteroOdd dropping PteroEffigy in mid-April 2025; PteroEffigy then contacted the domain eset.ydns[.]eu to deliver Kazuar v2. This places PteroEffigy in an intrusion chain supporting delivery of Turla malware, with ESET assessing that Gamaredon likely provided initial access to Turla on selected Ukrainian machines. High-confidence infrastructure/IOC directly mentioned for PteroEffigy includes the domain eset.ydns[.]eu.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The other five new tools - PteroDee, PteroCache, PteroDum, PteroOdd and PteroEffigy - are all lightweight downloaders that fetch the next payload, C2 information or additional malware.
...PteroOdd was used to drop another PowerShell downloader codenamed PteroEffigy, which ultimately contacted the "eset.ydns[.]eu" domain to deliver Kazuar v2...
Techniques & procedures
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique
Initial Access
Execution
2 techniques
Execution
IOCs tracked for this family
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A lightweight downloader used to fetch next-stage payloads, command-and-control information, or additional malware.
Gamaredon-associated tool/implant deployed during the observed co-compromises; specific functionality is not described in the provided content.
Custom Gamaredon tool used in compromises of Ukrainian machines; specific functionality not described in the provided content.
A Gamaredon PowerShell downloader used as an intermediate stage to retrieve and deliver Kazuar v2.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.