Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Pteranodon

Pteranodon

TLP:CLEAR
Family

Also known as: Pterodo

AI Analysis

· 1 day ago

Executive Summary

Pteranodon is a custom Windows backdoor used by the Russian APT group Gamaredon to establish long‑term remote control over infected hosts. It communicates with C&C servers via HTTP(S), supports credential theft and system enumeration, and maintains persistence through registry modifications. The malware’s stealthy profile necessitates proactive detection and monitoring measures.

Enhanced Description

Pteranodon is a custom Windows backdoor attributed to the cyber‑espionage group Gamaredon. The malware was first observed in analysis conducted by Palo Alto Networks in February 2017, where it was identified as a remote access trojan (RAT) designed to maintain persistence on compromised systems and provide attackers with persistent, covert control. Once deployed, Pteranodon establishes a connection to a command‑and‑control (C&C) server, typically via HTTP/HTTPS traffic. In addition to basic remote shell functionality it supports credential harvesting, keylogging, and system enumeration, allowing the adversary to acquire user passwords and gather detailed host information for lateral movement. The code employs typical anti‑analysis techniques such as disabling Windows security components, hiding itself in legitimate processes, and using encrypted communications to evade detection. Persistence mechanisms include modifying registry run keys and creating scheduled tasks. The malware’s modular design suggests it can be extended with additional backdoor exploits or data exfiltration modules. Impact-wise, Pteranodon enables Gamaredon to conduct long‑term espionage against corporate environments, steal intellectual property, and potentially pivot to other targets within the same network infrastructure. Its reliance on standard Windows primitives makes detection challenging without a layered security approach.

Key Capabilities

  • Establishes outbound HTTP/HTTPS connections to a command-and-control server
  • Implements persistence by writing to the Windows Run registry key
  • Harvests credentials via keylogging and credential dumping libraries
  • Enumerates system files, directories, and services for reconnaissance
  • Hides processes and disables certain security components to evade detection
  • Encrypts communications with the C&C server for stealth

ATT&CK Techniques

T1071.001
T1059
T1112
T1047
T1083

Recommended Actions

  • Deploy endpoint detection and response (EDR) solutions that flag outbound HTTP(S) connections to unknown domains.
  • Monitor registry modifications at "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" and similar persistence locations.
  • Enable file integrity monitoring to detect creation of suspicious executables. Implement network segmentation to restrict lateral movement if a host is compromised. Use threat‑intel feeds to block known C&C IPs and domains. Perform regular penetration testing or red team exercises focusing on remote access trojan detection.

Suggested Tags

Gamaredon
Pteranodon
Backdoor
Windows RAT
Command And Control
APT30
Russian APT
Credential Theft

Confidence Assessment

The confidence in the identification of Pteranodon as a Gamaredon backdoor is high due to corroborating reports from Palo Alto Networks. However, detailed technical specifics such as exact encryption algorithms, complete command set, and full persistence tactics are not fully documented, leaving gaps particularly around post‑infection payload delivery mechanisms and potential integration with other known RAT modules.

Description

Pteranodon is a custom backdoor used by Gamaredon Group. (Citation: Palo Alto Gamaredon Feb 2017)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.