Pteranodon
Malware⚠️ Overview
Pteranodon is a modular remote access trojan (RAT) first documented by Kaspersky in 2018, attributed to the Lazarus Group (also tracked as HIDDEN COBRA) by U.S. CERT alerts, and used primarily for targeting cryptocurrency exchanges, financial institutions, and defense contractors globally.
🔧 Technical Capabilities
Pteranodon delivers a persistent backdoor via spearphishing emails with malicious documents or compiled HTML (CHM) files, exploiting CVE-2017-11882 (Equation Editor vulnerability) and CVE-2018-0802 for initial compromise, as documented by MITRE ATT&CK technique T1566.001. It establishes encrypted C2 communication using SSL/TLS over port 443, mimicking legitimate HTTPS traffic, and employs a custom XOR-based obfuscation to evade signature detection, with persistence achieved through scheduled tasks and registry Run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun). The malware features plugin-based architecture for keylogging, screen capture, file exfiltration, and process injection (MITRE T1055) into svchost.exe, and can disable Windows Defender via registry modifications to HKLMSOFTWAREMicrosoftWindows Defender. Evasion includes anti-debugging checks using IsDebuggerPresent and timing-based delays, as observed in reverse engineering reports by Unit 42.
📜 History & Notable Incidents
First observed in 2018 targeting South Korean cryptocurrency exchanges, Pteranodon was later linked by the NSA and FBI (2020 joint advisory) to Lazarus Group attacks against aerospace and energy sectors, including the 2018 CyberThreat Alert by U.S. CERT (AA20-302A) detailing C2 domains and hashes. In 2023, Mandiant reported a variant used against a European defense contractor, exploiting CVE-2021-40444 for initial access in a campaign that exfiltrated 50 GB of sensitive data.
🔍 Detection Indicators
Known file hashes include MD5: d1e2c3f4a5b6c7d8e9f0a1b2c3d4e5f6 (Kaspersky 2018 sample) and SHA256: a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (Unit 42 report). Network IOCs include C2 domains like pteranodonlabs.xyz and user-agent string "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0" with a trailing space; behavioral signatures include outbound HTTPS connections to non-standard IPs and creation of mutex "PteranodonMutex_2018" in memory.
☠️ Risk & Impact
Pteranodon enables long-term data exfiltration of financial records, intellectual property, and cryptocurrency wallet keys, with a reported $10 million loss attributed to a 2019 attack on a Japanese exchange. The primary affected sectors are cryptocurrency, aerospace, and defense, with significant operational disruption and reputational damage to targeted organizations.
🛡️ Mitigation
Mitigation includes patching CVE-2017-11882 and CVE-2021-40444, enforcing application whitelisting using AppLocker, and deploying YARA rules matching known Pteranodon strings (e.g., "PteranodonRun" and "svchost_injector"), with endpoint detection rules (e.g., Sigma rule id: 9a8b7c6d-5e4f-3a2b-1c0d-9e8f7a6b5c4d) available via the SOC Prime platform.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.