FILEMembers
FILE

Pterodo Backdoor Hides Inside Fake Blender Install Path

A Gamaredon-linked Pterodo DLL masquerades under a GUID filename inside a genuine Blender Foundation directory, drawing 52 of 76 detections and unanimous malicious sandbox verdicts despite carrying no code-signing certificate. Its only network indicator, win-restore.ru, is a six-year-old dormant registration rather than fresh C2 infrastructure.

Sep 12, 2026, 14:56 (UTC+9)Last seenSep 12, 2026Severity74ByCTX TeamActorGamaredon GroupCTIGIOC3MITRE9RegionsCHCN

A Windows DLL flagged as trojan.pterodo/doina installs itself under a filepath that reads like a legitimate Blender Foundation component — C:\Program Files\Blender Foundation\Blender\A562C7DBA738DC65D3B7DEADE7FFC31D — a GUID-style filename sitting inside a real 3D-graphics software directory rather than a temp folder or a randomly generated string in %APPDATA%.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence