Pteranodon, also tracked as Pterodo, is a custom backdoor and deployment framework associated with the Russia-linked Gamaredon group (also tracked as UAC-0010/Armageddon), which Ukraine’s Security Service has tied to the FSB. By 2016, Gamaredon had shifted from off-the-shelf tooling to this custom framework, which later evolved into a more fragmented and modular malware ecosystem. The malware has been used in campaigns targeting Ukrainian organizations, including state authorities and other government-related victims, and has been observed as a follow-on payload after spear-phishing infections using malicious Office documents.
High-confidence capabilities described in the content include loading additional payloads, executing arbitrary commands, collecting system data, capturing screenshots at configurable intervals, stealing files from local systems and USB drives, and exfiltrating collected data and screenshots to command-and-control servers. It creates subdirectories under %Temp%\reports% and stores screenshot JPEG files in C:\Users<user>\AppData\Roaming\Microsoft\store before exfiltration. It can use anti-detection logic to identify sandbox environments.
For persistence and execution, Pteranodon schedules tasks to invoke its components. The content also states it can use mshta.exe to execute a remotely hosted HTA file, and can delete interfering files, temporary files, and even itself after the initial script executes. CERT-UA and the Foreign Intelligence Service of Ukraine reported new Pterodo-type modifications on computers of Ukrainian state authorities, describing the malware as collecting system information, regularly sending it to C2, and awaiting further commands. The malware is repeatedly linked in the content to Gamaredon operations against Ukraine.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Документи ... містили шкідливий код для експлуатації відомої вразливості «Microsoft Office» CVE-2017-0199 ... що надає змогу зловмиснику виконати довільний код на пристрої користувача, при відкритті інфікованого файлу.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this particular campaign, once Gamaredon gained an initial foothold through the malicious Word document, the group was observed running reconnaissance commands and deploying the “Pterodo” backdoor to maintain persistence.
Indicators of Compromise (IoCs):- ... Malware Pterodo Backdoor associated with UAC-0010 (Gamaredon)
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware executable sets up as a task as “schtasks /Create /SC MINUTE /MO 12 /F /tn Word.Downdloads /tr” to run every 12 minutes
the attackers proceed to download another variant of their “Pterodo” backdoor and begin running additional scripts and creating scheduled tasks to run every few minutes.
Once opened, the Word document will execute a heavily obfuscated macro called “xdm”. This PowerShell script decodes and executes a second PowerShell script (also obfuscated), which reports back to the command and control server.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The malware executable sets up as a task as “schtasks /Create /SC MINUTE /MO 12 /F /tn Word.Downdloads /tr” to run every 12 minutes
The malware executable sets up as a task as “schtasks /Create /SC MINUTE /MO 12 /F /tn Word.Downdloads /tr” to run every 12 minutes
One of the notable features of the malware Interop component is its usage of the fake Microsoft digital certificate belonging to Microsoft Time-Stamp Service.
Many entries explicitly describe deleting artifacts 'to cover tracks,' 'evade detection,' 'remove evidence,' 'reduce their footprint,' or as part of 'post-intrusion cleanup process.' Examples include APT28 deleting files to cover tracks, FIN5 using SDelete to clean up the environment, and Dragonfly deleting operational files as part of cleanup.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
Multiple actors and malware families are described as using mshta/mshta.exe (including renamed mshta.exe) to execute malicious scripts/HTA/HTML/VBScript/JavaScript, download and run payloads from remote servers, and in one case help schedule tasks for persistence.
Agent Tesla has the ability to perform anti-sandboxing and anti-virtualization checks. Bisonal can check to determine if the compromised system is running on VMware. Bumblebee has the ability to perform anti-virtualization checks. CozyCar will check to ensure it is not being executed inside a virtual machine or a known malware analysis sandbox environment. Metamorfo has embedded a "vmdetect.exe" executable to identify virtual machines at the beginning of execution. RTM can detect if it is running within a sandbox or other virtualized analysis environment. Saint Bear contains several anti-analysis and anti-virtualization checks.
At the final stage of the attack, the group deploys remote access software and information-gathering tools.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Agent Tesla has the ability to perform anti-sandboxing and anti-virtualization checks. Bisonal can check to determine if the compromised system is running on VMware. Bumblebee has the ability to perform anti-virtualization checks. CozyCar will check to ensure it is not being executed inside a virtual machine or a known malware analysis sandbox environment. Metamorfo has embedded a "vmdetect.exe" executable to identify virtual machines at the beginning of execution. RTM can detect if it is running within a sandbox or other virtualized analysis environment. Saint Bear contains several anti-analysis and anti-virtualization checks.
This virus collects system data, regularly sends it to command-control servers and expects further commands.
Tool Telegram Used as C2 channel by UAC-0010 and others Tool Telegraph Used for IP-based C2 routing by UAC-0010
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware framework previously used by Gamaredon before its tooling evolved into more fragmented modular malware families.
A custom-built framework previously used by Gamaredon before its tooling evolved into more fragmented and modular malware variants.
A historical custom backdoor and deployment framework used by Gamaredon. It loaded additional payloads, executed arbitrary commands, captured screenshots, and stole files from local systems and USB drives for exfiltration.
Backdoor associated with UAC-0010 (Gamaredon).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.