PteroPaste is a custom Gamaredon malware tool used in cyberespionage operations against Ukrainian targets. It emerged as one of the more capable additions to Gamaredon’s 2025 PowerShell-based arsenal and combines multiple functions in a single component: downloader behavior, USB weaponization, and a runner or orchestration role used for persistence and execution of additional malicious components. The malware repeatedly checks compromised Windows systems for connected USB drives and can copy a malicious downloader onto removable media, disguising it as a shortcut to facilitate execution. It has also been used to infect USB drives and network drives with malicious LNK-based propagation mechanisms, supporting lateral movement inside compromised environments.
PteroPaste is associated with Gamaredon, a Russia-aligned threat actor widely linked to sustained espionage activity against Ukrainian government and military institutions. Its operational purpose is to extend access within victim networks and retrieve follow-on payloads over encrypted channels while helping conceal backend infrastructure through legitimate online services and tunneling layers. Reported variants have staged encrypted payloads through public services and later retrieved encrypted command-and-control information from cloud storage before connecting to infrastructure hidden behind tunnel services. Some reporting also attributes Dropbox-based data upload behavior to PteroPaste.
The malware has additionally been observed in incidents linked to cooperation between Gamaredon and Turla, where PteroPaste and other Gamaredon tools were used to deploy Turla’s Kazuar implant on selected Ukrainian systems. This suggests PteroPaste can serve not only as a propagation and downloader utility but also as an enabler for delivery of higher-value follow-on espionage payloads. Its design reflects Gamaredon’s broader tradecraft preference for simple but adaptable tooling that can be updated quickly and combined flexibly across spearphishing-led intrusion chains and post-compromise spread via removable and networked media.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Based on the public reporting, it seems that PteroOdd and PteroPaste, two custom malware families attributed to Gamaredon, deployed Kazuar, a malware attributed to Turla.
The standout among the new tools is PteroPaste, which is considerably more complex than the others. It combines a downloader, a USB weaponizer, and a runner component used for persistence and orchestration.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The group tracked as Gamaredon spent the first half of the year developing six new PowerShell-based downloaders.
Gamaredon continued to refine its techniques for protecting its network infrastructure and hiding its C&C servers... the group’s reliance on third-party services grew significantly, with tunnel services and serverless worker platforms becoming an increasingly important part of how it hid its real back-end infrastructure.
They also abused multiple legitimate messaging, social media, blogging, and paste services as dead drops for resolving C&C servers and distributing payloads.
Gamaredon abused multiple legitimate messaging, social media, blogging, and paste services as dead drops for resolving C&C servers... In 2025, Gamaredon abused numerous services in this way: Telegram channels, Telegra.ph, Teletype, rentry.co, write.as, Dropbox, GoFile, DEV Community, Mastodon, lesma, nopaste.net, and Paste.ee.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware family attributed in cited public reporting to Gamaredon; mentioned only as an external comparison case.
A Gamaredon PowerShell-based tool used for lateral movement and part of the group's expanded custom malware set.
A Gamaredon tool used to weaponize USB drives and download additional PowerShell payloads over an encrypted channel; also used to facilitate lateral movement via malicious LNK-based propagation.
A multi-component Gamaredon tool that combines downloader, USB propagation/weaponization, and runner functionality to maintain persistence and execute additional malicious components. Newer versions retrieve encrypted C2 information from Dropbox and connect to infrastructure hidden behind tunneling services; earlier versions used Rentry to stage encrypted payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.