PteroPaste is a Gamaredon malware family and one of six new PowerShell-based tools documented in the group’s 2025 operations against Ukraine. It is described as the most complex of the newly introduced tools, combining downloader functionality, a USB weaponizer, and a runner component used for persistence and orchestration/execution of additional malicious components. Gamaredon used PteroPaste for lateral movement by infecting USB drives and network drives with malicious LNK files; opening those LNK files triggered retrieval of downloader malware. On compromised systems, PteroPaste repeatedly checks for connected USB drives and attempts to copy a malicious downloader script onto them, disguising it by using a Word document name from the infected host and appending a .lnk extension. Reporting also states it can download additional PowerShell payloads via an encrypted channel. Earlier variants used Rentry to stage encrypted payloads, while newer versions retrieved encrypted command-and-control information from Dropbox, decrypted it locally, and then connected to backend infrastructure concealed behind tunneling services. Some reporting also states PteroPaste uploads stolen data to Dropbox. The malware is associated with the Russia-aligned Gamaredon APT, which in 2025 targeted Ukrainian governmental and military institutions in cyberespionage campaigns. ESET also reported that PteroPaste, together with PteroOdd, was used in April and June 2025 to deploy Turla’s Kazuar v2 on selected Ukrainian systems, supporting assessments of operational cooperation between Gamaredon and Turla. A specifically reported IOC is the IP address 91.231.182[.]187, from which PteroPaste was observed dropping and installing Kazuar v2 named ekrn.ps1 on June 5-6, 2025.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Gamaredon also employed PteroLNK and PteroPaste for lateral movement via infected USB and network drives... Six new PowerShell tools, including PteroDee, PteroCache, PteroDum, PteroOdd, PteroEffigy, and PteroPaste, were introduced...
The standout among the new tools is PteroPaste, which is considerably more complex than the others. It combines a downloader, a USB weaponizer, and a runner component used for persistence and orchestration.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The group tracked as Gamaredon spent the first half of the year developing six new PowerShell-based downloaders.
Gamaredon continued to refine its techniques for protecting its network infrastructure and hiding its C&C servers... the group’s reliance on third-party services grew significantly, with tunnel services and serverless worker platforms becoming an increasingly important part of how it hid its real back-end infrastructure.
They also abused multiple legitimate messaging, social media, blogging, and paste services as dead drops for resolving C&C servers and distributing payloads.
Gamaredon abused multiple legitimate messaging, social media, blogging, and paste services as dead drops for resolving C&C servers... In 2025, Gamaredon abused numerous services in this way: Telegram channels, Telegra.ph, Teletype, rentry.co, write.as, Dropbox, GoFile, DEV Community, Mastodon, lesma, nopaste.net, and Paste.ee.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Gamaredon PowerShell-based tool used for lateral movement and part of the group's expanded custom malware set.
A Gamaredon tool used to weaponize USB drives and download additional PowerShell payloads over an encrypted channel; also used to facilitate lateral movement via malicious LNK-based propagation.
A multi-component Gamaredon tool that combines downloader, USB propagation/weaponization, and runner functionality to maintain persistence and execute additional malicious components. Newer versions retrieve encrypted C2 information from Dropbox and connect to infrastructure hidden behind tunneling services; earlier versions used Rentry to stage encrypted payloads.
A Gamaredon PowerShell-based downloader that monitors for USB drives, copies a malicious downloader onto them using a disguised .lnk filename, and uploads stolen data to Dropbox.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.