Also known as: Pterodo
Executive Summary
Pteranodon is a custom Windows backdoor used by the Russian APT group Gamaredon to establish long‑term remote control over infected hosts. It communicates with C&C servers via HTTP(S), supports credential theft and system enumeration, and maintains persistence through registry modifications. The malware’s stealthy profile necessitates proactive detection and monitoring measures.
Enhanced Description
Pteranodon is a custom Windows backdoor attributed to the cyber‑espionage group Gamaredon. The malware was first observed in analysis conducted by Palo Alto Networks in February 2017, where it was identified as a remote access trojan (RAT) designed to maintain persistence on compromised systems and provide attackers with persistent, covert control. Once deployed, Pteranodon establishes a connection to a command‑and‑control (C&C) server, typically via HTTP/HTTPS traffic. In addition to basic remote shell functionality it supports credential harvesting, keylogging, and system enumeration, allowing the adversary to acquire user passwords and gather detailed host information for lateral movement. The code employs typical anti‑analysis techniques such as disabling Windows security components, hiding itself in legitimate processes, and using encrypted communications to evade detection. Persistence mechanisms include modifying registry run keys and creating scheduled tasks. The malware’s modular design suggests it can be extended with additional backdoor exploits or data exfiltration modules. Impact-wise, Pteranodon enables Gamaredon to conduct long‑term espionage against corporate environments, steal intellectual property, and potentially pivot to other targets within the same network infrastructure. Its reliance on standard Windows primitives makes detection challenging without a layered security approach.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the identification of Pteranodon as a Gamaredon backdoor is high due to corroborating reports from Palo Alto Networks. However, detailed technical specifics such as exact encryption algorithms, complete command set, and full persistence tactics are not fully documented, leaving gaps particularly around post‑infection payload delivery mechanisms and potential integration with other known RAT modules.
Pteranodon is a custom backdoor used by Gamaredon Group. (Citation: Palo Alto Gamaredon Feb 2017)