PteroStew is a general-purpose VBScript downloader used by the Russia-aligned Gamaredon APT. It was discovered in October 2024 and is described as similar to earlier Gamaredon downloaders such as PteroSand and PteroRisk, but with the notable characteristic of storing its code in alternate data streams associated with benign files on the victim system. ESET identified it as one of six new Gamaredon malware tools introduced in 2024. Gamaredon’s broader delivery activity in 2024 relied heavily on spearphishing against Ukrainian governmental institutions, typically using malicious RAR, ZIP, and 7z archives or XHTML files with HTML smuggling to deliver HTA or LNK files that executed VBScript downloaders; ESET also observed a rarer campaign using malicious hyperlinks and LNK files that launched PowerShell from Cloudflare-hosted domains. PteroStew was also observed on Ukrainian machines in early 2025 during incidents where Gamaredon and Turla co-compromised the same systems; in those cases, Gamaredon deployed tools including PteroLNK, PteroStew, PteroOdd, PteroEffigy, and PteroGraphin, while Turla deployed Kazuar v3. High-confidence associations in the provided content tie PteroStew to Gamaredon operations targeting Ukrainian government-related entities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PteroStew : A new general-purpose VBScript downloader discovered in October 2024, similar to previously known downloaders (e.g., PteroSand, PteroRisk), but that notably stores its code in alternate data streams associated with benign files on the victim’s system.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Gamaredon-associated tool/implant deployed on compromised Ukrainian systems as part of the group’s toolset used alongside other Ptero* components.
Custom Gamaredon tool used in compromises of Ukrainian machines; specific functionality not described in the provided content.
VBScript downloader that stores code in NTFS alternate data streams associated with benign files.
A general-purpose VBScript downloader that stores its code in alternate data streams associated with benign files for stealth.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.