PteroLNK is a Gamaredon malware tool/weaponizer used for lateral movement and propagation. It is associated with the Russia-aligned Gamaredon APT (also tracked as Shuckworm, Armageddon, Primitive Bear, ACTINIUM, Callisto, and Aqua Blizzard), which has targeted Ukrainian government, military, law-enforcement, and defense-related entities. PteroLNK is used to infect removable USB drives and mapped network drives with malicious LNK files; when a victim opens one of those shortcut files, it triggers retrieval of downloader malware and follow-on payloads. Reporting states that the VBScript version of PteroLNK was enhanced in early 2024 to weaponize mapped network drives in addition to USB drives, expanding its lateral-movement capability. During the second half of 2024, it received updates that improved obfuscation, complicated LNK creation, and used registry-based techniques to hide files and file extensions. PteroLNK has also been referenced in 2025 reporting as part of Gamaredon’s continuing operations against Ukraine and was observed among Gamaredon tools deployed on systems that were also compromised by Turla, which installed the Kazuar backdoor. High-confidence behavior directly mentioned in the source content is propagation via malicious LNK files on USB and network drives for lateral movement within victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Gamaredon also employed PteroLNK and PteroPaste for lateral movement via infected USB and network drives...
20 distinct techniques documented for this family, organized by ATT&CK tactic.
“establishing persistence through scheduled tasks… The downloader payload is scheduled to execute every 3 minutes, while the LNK dropper script runs every 9 minutes.”
These files delivered malicious HTA or LNK files that executed embedded VBScript downloaders such as PteroSand.
“establishing persistence through scheduled tasks… The downloader payload is scheduled to execute every 3 minutes, while the LNK dropper script runs every 9 minutes.”
“concealing its activities by modifying Windows Explorer settings to hide files… modifies the registry in order to hide hidden files and folders, extensions and protected OS files.”
“establishing persistence through scheduled tasks… The downloader payload is scheduled to execute every 3 minutes, while the LNK dropper script runs every 9 minutes.”
Throughout the second half of 2024, it received multiple incremental updates, including improved obfuscation
“replacing existing files and folders with deceptive shortcuts… creates a malicious shortcut that mimics the original file… chooses… military-themed decoy filenames in Ukrainian”
“Shortcuts are configured to execute the main PteroLNK VBScript malware… via mshta.exe.”
“enumerates local and mapped drives… propagate through local and network drives”
“sends… HTTP GET request… using its custom User-Agent… DDR at telegra.ph… teletype.in… trycloudflare.com tunnel…”
“Cloudflare quick tunnel address… hosted on trycloudflare.com… adopted by threat actors… traverse network detection by blending with legitimate traffic.”
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Gamaredon tool used for lateral movement through infected USB and network drives.
A Gamaredon weaponizer used for lateral movement by infecting USB and network drives with malicious LNK files that retrieve downloader malware when opened.
A previously known Gamaredon tool referenced as having important updates in 2025, but its functionality is not described in this content.
Gamaredon tool used to propagate/execute malicious LNK files (including via removable drives) to facilitate initial access and infection in targeted environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.