Pteranodon
MITRE ATT&CK: S0147 View on attack.mitre.org
Aliases: Pterodo, Pteranodon
- First seen
- 2016-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 15:45:11
Targeted industries: government-and-public-sector
Targeted regions: country_code:ua
Context
Pteranodon is a custom backdoor used by Gamaredon Group.
Detection coverage
- 1 YARA rules
- 322 Sigma rules
Malware & tools used
- Screen Capture (attack-pattern)
- Windows Command Shell (attack-pattern)
- Native API (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Web Protocols (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Dynamic API Resolution (attack-pattern)
- Visual Basic (attack-pattern)
- Rundll32 (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- File Deletion (attack-pattern)
- Local Data Staging (attack-pattern)
- Virtualization/Sandbox Evasion (attack-pattern)
- Mshta (attack-pattern)
- Scheduled Task (attack-pattern)
Used by threat actors
- Gamaredon Group (threat-actor)
Detection rules
- MALPEDIA_Win_Pteranodon_Auto (yara-rule)
Reports & references
- Palo Alto Unit 42 — Unit 42 Title Gamaredon Group Toolset Evolution (report)
- MITRE ATT&CK — G0047 (report)
- Broadcom/Symantec — Shuckworm Gamaredon Espionage Ukraine (report)
- Microsoft — Actinium Targets Ukrainian Organizations (report)
- ESET — Gamaredon Group Grows Its Game (report)
- Palo Alto Unit 42 — Gamaredon Primitive Bear Ukraine Update 2021 (report)
- Microsoft — Actinium Targets Ukrainian Organizations (report)
- researchcenter.paloaltonetworks.com — Unit 42 Title Gamaredon Group Toolset Evolution (report)
- secureworks.com — Iron Tilden (report)
- ssu.gov.ua — Technical%20Report%20Armagedon (report)
- blog.synapticsystems.de — Inside Gamaredon 2025 Zero Click Espionage At Scale (report)
- threatmon.io — Beyond Bullets And Bombs An Examination Of Armageddon Groups Cyber Warfare Against Ukraine (report)
- threatstop.com — Gamaredon Group Understanding The Russian Apt (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Pteranodon (report)
- vkremez.com — Lets Learn Deeper Dive Into Gamaredon (report)
- blogs.blackberry.com — Gamaredon Leverages Microsoft Office Docs To Target Ukraine Government (report)
- CERT-UA — 42 (report)
- bleepingcomputer.com — Russian Gamaredon Hackers Use 8 New Malware Payloads In Attacks (report)
- rnbo.gov.ua — Gamaredon Activity (report)
- threatrecon.nshc.net — Sectorc08 Multi Layered Sfx Recent Campaigns Target Ukraine (report)
- Broadcom/Symantec — Shuckworm Intense Campaign Ukraine (report)
- elastic.co — Playing Defense Against Gamaredon Group (report)
- labs.sentinelone.com — Pro Russian Cyberspy Gamaredon Intensifies Ukrainian Security Targeting (report)
- threatmon.io — Cybergun Technical Analysis Of The Armageddons Infostealer (report)
- CERT-UA — 46 (report)
External references
- mitre-attack — S0147
- Pterodo
- Palo Alto Gamaredon Feb 2017
- Secureworks IRON TILDEN Profile
- Symantec Shuckworm January 2022
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy