
Pterodo Backdoor Hides Inside Fake Blender Install Path
A Gamaredon-linked Pterodo DLL masquerades under a GUID filename inside a genuine Blender Foundation directory, drawing 52 of 76 detections and unanimous malicious sandbox verdicts despite carrying no code-signing certificate. Its only network indicator, win-restore.ru, is a six-year-old dormant registration rather than fresh C2 infrastructure.
A Windows DLL flagged as trojan.pterodo/doina installs itself under a filepath that reads like a legitimate Blender Foundation component — C:\Program Files\Blender Foundation\Blender\A562C7DBA738DC65D3B7DEADE7FFC31D — a GUID-style filename sitting inside a real 3D-graphics software directory rather than a temp folder or a randomly generated string in %APPDATA%.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read