PteroLNK
PteroLNK is a Gamaredon weaponizer used for propagation and lateral movement by infecting removable USB drives and mapped network drives with malicious Windows LNK files. When a victim opens one of the malicious shortcut files, it triggers retrieval and execution of downloader malware, including VBScript-based payload chains associated with Gamaredon. ESET reported that the VBScript version of PteroLNK was enhanced in early 2024 to weaponize mapped network drives in addition to USB drives, expanding its spread within compromised environments. During the second half of 2024, it received updates that improved obfuscation, complicated LNK creation, and used registry-based techniques to hide files and file extensions. The tool has been associated with Gamaredon’s broader spear-phishing and post-compromise activity targeting Ukrainian governmental, military, law-enforcement, and defense-related entities. ESET also observed PteroLNK deployed on Ukrainian machines in early 2025 in incidents where Gamaredon activity overlapped with Turla operations involving the Kazuar backdoor.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Gamaredon's attacks are known to rely on weaponizers like PteroLNK and PteroPaste to facilitate lateral movement by infecting USB drives and network drives with malicious LNK files that, when opened by an unsuspecting user, trigger the retrieval of downloader malware.
Techniques & procedures
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique
Initial Access
Execution
4 techniques
Execution
“establishing persistence through scheduled tasks… The downloader payload is scheduled to execute every 3 minutes, while the LNK dropper script runs every 9 minutes.”
These files delivered malicious HTA or LNK files that executed embedded VBScript downloaders such as PteroSand.
Persistence
4 techniques
Persistence
“establishing persistence through scheduled tasks… The downloader payload is scheduled to execute every 3 minutes, while the LNK dropper script runs every 9 minutes.”
“concealing its activities by modifying Windows Explorer settings to hide files… modifies the registry in order to hide hidden files and folders, extensions and protected OS files.”
Privilege Escalation
3 techniques
Privilege Escalation
“establishing persistence through scheduled tasks… The downloader payload is scheduled to execute every 3 minutes, while the LNK dropper script runs every 9 minutes.”
Stealth
5 techniques
Stealth
Throughout the second half of 2024, it received multiple incremental updates, including improved obfuscation
“replacing existing files and folders with deceptive shortcuts… creates a malicious shortcut that mimics the original file… chooses… military-themed decoy filenames in Ukrainian”
“Shortcuts are configured to execute the main PteroLNK VBScript malware… via mshta.exe.”
Defense Impairment
1 technique
Defense Impairment
Discovery
3 techniques
Discovery
“enumerates local and mapped drives… propagate through local and network drives”
Lateral Movement
2 techniques
Lateral Movement
Command and Control
4 techniques
Command and Control
“sends… HTTP GET request… using its custom User-Agent… DDR at telegra.ph… teletype.in… trycloudflare.com tunnel…”
“Cloudflare quick tunnel address… hosted on trycloudflare.com… adopted by threat actors… traverse network detection by blending with legitimate traffic.”
Recent activity
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Gamaredon weaponizer used for lateral movement by infecting USB and network drives with malicious LNK files that retrieve downloader malware when opened.
A previously known Gamaredon tool referenced as having important updates in 2025, but its functionality is not described in this content.
Gamaredon tool used to propagate/execute malicious LNK files (including via removable drives) to facilitate initial access and infection in targeted environments.
Custom Gamaredon tool used in compromises of Ukrainian machines; specific functionality not described in the provided content.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.