
Gamaredon's Pterodo Loader Stalls Sandboxes to Hide Its Real Payload
A Pterodo-family loader tied to Gamaredon reads the CPU clock and stalls execution before unpacking a second payload appended past its own file boundary. The technique, not the actor label, is what this record actually documents in detail.
A Pterodo-family loader flagged by 57 of 77 antivirus engines carries something more interesting than its detection score. The binary reads the CPU timer directly to work out whether it is running inside an analysis environment, deliberately stalls for long periods before doing anything else, and only then reaches past the end of its own file to load a second payload that was appended there as raw bytes [T1497.003, T1106].
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read