Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 2 actors

PteroPaste

PteroPaste is a custom Gamaredon malware family and one of six new PowerShell-based tools documented by ESET in relation to the Russia-linked threat group’s 2025 operations. It is described as the most complex of the newly identified tools, combining downloader, USB weaponization, and runner functionality to provide persistence and execute additional malicious components. Newer variants retrieve encrypted command-and-control information from Dropbox, decrypt it on the infected host, and then connect to backend infrastructure concealed behind tunneling services; an earlier version used Rentry to stage encrypted payloads. The broader Gamaredon ecosystem also used legitimate services such as Telegram, Dropbox, GoFile, and Mastodon for dead-drop retrieval of infrastructure information, and hid backend servers behind Cloudflare Workers, Microsoft devtunnels.ms, Loophole, and previously Cloudflare Tunnels.

ESET reported PteroPaste being used in attacks against Ukrainian targets during 2025, including high-value systems. In April and June 2025, Gamaredon tools PteroOdd and PteroPaste were used to deploy Turla’s Kazuar v2 implant on compromised Ukrainian machines, and ESET assessed with high confidence that Gamaredon was providing initial access to Turla. On June 5–6, 2025, ESET observed a PowerShell downloader referred to as PteroPaste dropping and installing Kazuar v2 from 91.231.182[.]187 on two machines in Ukraine; the installed script was named ekrn.ps1, which ESET assessed may have been intended to masquerade as the legitimate ESET component ekrn.exe. Reported likely infection vectors for related Gamaredon activity include spear-phishing and malicious .lnk files on removable drives, and later in 2025 Gamaredon also exploited CVE-2025-8088 in WinRAR via crafted archives that placed malicious HTA downloaders in Startup folders for persistence. The activity is associated with Gamaredon, a threat group long linked to Russia’s FSB and known for targeting Ukrainian military, judiciary, law enforcement, non-profit, governmental, and defense-sector entities.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Gamaredon Group

Among its six new tools, Eset said PteroPaste is the most complex, combining a downloader, a USB weaponizer and a runner component all in one for persistence and execution of other malicious components.

via govinfosecuritygovinfosecurity.com
Turla

Among its six new tools, Eset said PteroPaste is the most complex, combining a downloader, a USB weaponizer and a runner component all in one for persistence and execution of other malicious components.

via govinfosecuritygovinfosecurity.com
MITRE ATT&CK

Techniques & procedures

8 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1091Replication Through Removable MediaEvidence1

Among its six new tools, Eset said PteroPaste is the most complex, combining a downloader, a USB weaponizer and a runner component all in one for persistence and execution of other malicious components.

T1566PhishingEvidence2

The group tracked as Gamaredon spent the first half of the year developing six new PowerShell-based downloaders and shifted focus in the second half to launching at least 35 spear-phishing campaigns.

Execution

2 techniques
T1059Command and Scripting InterpreterEvidence3

The group tracked as Gamaredon spent the first half of the year developing six new PowerShell-based downloaders.

T1059.001PowerShellEvidence1

The group tracked as Gamaredon spent the first half of the year developing six new PowerShell-based downloaders.

Lateral Movement

1 technique
T1091Replication Through Removable MediaEvidence1

Among its six new tools, Eset said PteroPaste is the most complex, combining a downloader, a USB weaponizer and a runner component all in one for persistence and execution of other malicious components.

Command and Control

4 techniques
T1090.002External ProxyEvidence1

The threat actor also started hiding its back-end infrastructure behind Cloudflare workers, Microsoft's dev tunnels and reverse proxy platform Loophole...

T1102Web ServiceEvidence1

The group placed infrastructure information on legitimate services, including Telegram, Dropbox, GoFile and Mastodon, for the malware to fetch it from there.

T1102.001Dead Drop ResolverEvidence1

...using 'dead drops,' a traditional espionage trick, to store command and control information in a legitimate service like Telegram for the malware to retrieve later... The group placed infrastructure information on legitimate services, including Telegram, Dropbox, GoFile and Mastodon, for the malware to fetch it from there.

T1105Ingress Tool TransferEvidence2

The other five new tools - PteroDee, PteroCache, PteroDum, PteroOdd and PteroEffigy - are all lightweight downloaders that fetch the next payload, C2 information or additional malware.

INDICATORS OF COMPROMISE

IOCs tracked for this family

2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

Other
1 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
uri●●●●●●●●●●●●View more in apptoday
ip.v4●●●●●●●●●●●●View more in app9 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching2

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping8

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.