PteroOdd is a Gamaredon malware family and one of six new PowerShell-based tools the group introduced in 2025. It is consistently described as a lightweight downloader, specifically a tiny PowerShell downloader used to retrieve a single PowerShell payload via the Telegra.ph API. Reporting states it fetches the next-stage payload or additional malware, and in observed attack chains PteroGraphin downloaded PteroOdd, which then retrieved a payload from Telegraph to execute Turla’s Kazuar backdoor.
The malware is associated with the Russia-aligned Gamaredon threat actor and was used in operations targeting Ukrainian government and military organizations during 2025. Multiple sources in the content indicate PteroOdd appeared mainly in incidents linked to operational collaboration between Gamaredon and Turla. Across incidents observed between February and June 2025, Gamaredon tooling including PteroOdd was used to deploy or relaunch Turla’s Kazuar malware, including Kazuar v2 and Kazuar v3. In April, PteroOdd and PteroPaste were used to deploy Kazuar v2 installers. On co-compromised systems, Gamaredon deployed tools including PteroOdd alongside PteroLNK, PteroStew, PteroEffigy, and PteroGraphin, while Turla deployed Kazuar.
The broader intrusion context in the content ties Gamaredon activity to spear-phishing campaigns, archive attachments, XHTML files with HTML smuggling, malicious HTA downloaders, and in some cases exploitation of WinRAR vulnerability CVE-2025-8088 for persistence via the Windows Startup folder, but the content does not directly attribute those initial-access mechanisms specifically to PteroOdd itself. High-confidence infrastructure and behavioral details directly tied to PteroOdd include use of the Telegra.ph API / Telegraph for payload retrieval. Additional observed related indicators in one reported chain include delivery of Kazuar-related payloads and communication involving the domain eset.ydns[.]eu, though that infrastructure is described in the wider chain rather than as exclusive to PteroOdd.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Six new PowerShell tools, including PteroDee, PteroCache, PteroDum, PteroOdd, PteroEffigy, and PteroPaste, were introduced, broadening their custom malware capabilities.
PteroOdd for fetching a single PowerShell payload using the Telegra.ph API and likely used in campaigns in which the Gamaredon actors collaborated with Turla
8 distinct techniques documented for this family, organized by ATT&CK tactic.
...use of a wide range of legitimate services as data exfiltration channels and dead drop resolvers... hidden behind tunnels or serverless workers.
They also abused multiple legitimate messaging, social media, blogging, and paste services as dead drops for resolving C&C servers and distributing payloads.
Gamaredon abused multiple legitimate messaging, social media, blogging, and paste services as dead drops for resolving C&C servers... In 2025, Gamaredon abused numerous services in this way: Telegram channels, Telegra.ph, Teletype, rentry.co, write.as, Dropbox, GoFile, DEV Community, Mastodon, lesma, nopaste.net, and Paste.ee.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
One of six newly introduced Gamaredon PowerShell tools expanding the group's malware arsenal.
A new Gamaredon PowerShell tool that fetches a single PowerShell payload via the Telegra.ph API; the article notes it was likely used in campaigns involving collaboration with Turla.
A lightweight downloader used to fetch next-stage payloads, command-and-control information, or additional malware.
A small downloader that retrieves a single PowerShell payload via the Telegra.ph API; observed mainly in activity connected to Gamaredon's collaboration with Turla.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.