PteroOdd is a lightweight PowerShell-based downloader associated with the Russia-aligned Gamaredon threat group. It is used to retrieve a single next-stage PowerShell payload, notably via the Telegra.ph API, and execute follow-on malware during intrusion chains targeting Ukrainian government and military organizations. The tool forms part of Gamaredon’s broader ecosystem of simple, rapidly updated components designed to support espionage operations through modular staging, payload delivery, and infrastructure concealment using legitimate online services.
PteroOdd has been observed in campaigns in 2025 alongside other Gamaredon tooling such as PteroGraphin, PteroPaste, and PteroEffigy. It has been used after earlier-stage compromise activity, including spearphishing-delivered infection chains and malicious LNK-based propagation associated with Gamaredon operations. In documented cases, PteroOdd functioned as an intermediate downloader that fetched additional PowerShell content and enabled deployment of Turla’s Kazuar backdoor on selected Ukrainian systems. This activity is notable as evidence of operational collaboration in which Gamaredon appears to have provided access and delivery support for Turla’s more advanced espionage implant.
The malware targets Windows environments and is consistent with Gamaredon’s preference for numerous narrowly scoped tools rather than monolithic implants. Its role is primarily payload retrieval and execution within post-compromise workflows, helping operators stage additional malware while blending command-and-control or payload hosting into trusted third-party services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Based on the public reporting, it seems that PteroOdd and PteroPaste, two custom malware families attributed to Gamaredon, deployed Kazuar, a malware attributed to Turla.
PteroOdd for fetching a single PowerShell payload using the Telegra.ph API and likely used in campaigns in which the Gamaredon actors collaborated with Turla
8 distinct techniques documented for this family, organized by ATT&CK tactic.
...use of a wide range of legitimate services as data exfiltration channels and dead drop resolvers... hidden behind tunnels or serverless workers.
They also abused multiple legitimate messaging, social media, blogging, and paste services as dead drops for resolving C&C servers and distributing payloads.
Gamaredon abused multiple legitimate messaging, social media, blogging, and paste services as dead drops for resolving C&C servers... In 2025, Gamaredon abused numerous services in this way: Telegram channels, Telegra.ph, Teletype, rentry.co, write.as, Dropbox, GoFile, DEV Community, Mastodon, lesma, nopaste.net, and Paste.ee.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware family attributed in cited public reporting to Gamaredon; mentioned as an example of possible inter-group collaboration.
One of six newly introduced Gamaredon PowerShell tools expanding the group's malware arsenal.
A new Gamaredon PowerShell tool that fetches a single PowerShell payload via the Telegra.ph API; the article notes it was likely used in campaigns involving collaboration with Turla.
A lightweight downloader used to fetch next-stage payloads, command-and-control information, or additional malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.