Anchor
MITRE ATT&CK: S0504 View on attack.mitre.org
Aliases: Anchor_DNS, Anchor
- First seen
- 2018-01-01 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Operating systems
- linux, windows
- Last IoC activity
- 2026-05-21 19:31:27
- Profile updated
- 2026-07-07 12:41:08
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical
Context
Anchor is one of a family of backdoor malware that has been used in conjunction with TrickBot on selected high profile targets since at least 2018.
Detection coverage
- 1 YARA rules
- 474 Sigma rules
Malware & tools used
- Non-Application Layer Protocol (attack-pattern)
- Windows Command Shell (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Execution Guardrails (attack-pattern)
- System Information Discovery (attack-pattern)
- Scheduled Task (attack-pattern)
- Cron (attack-pattern)
- Unix Shell (attack-pattern)
- Web Protocols (attack-pattern)
- Code Signing (attack-pattern)
- DNS (attack-pattern)
- Windows Service (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- File Deletion (attack-pattern)
- Software Packing (attack-pattern)
- NTFS File Attributes (attack-pattern)
- Service Execution (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Fallback Channels (attack-pattern)
Used by threat actors
- Wizard Spider (threat-actor)
Detection rules
- MALPEDIA_Win_Anchor_Auto (yara-rule)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- cybereason.com — Dropping Anchor From A Trickbot Infection To The Discovery Of The Anchor Malware (report)
- CrowdStrike — Report2021Gtr (report)
- securityintelligence.com — Itg08 Aka Fin6 Partners With Trickbot Gang Uses Anchor Framework (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- bleepingcomputer.com — Karakurt Revealed As Data Extortion Arm Of Conti Cybercrime Syndicate (report)
- netscout.com — Dropping Anchor (report)
- medium.com — Anchor Dns Malware Family Goes Cross Platform D807Ba13Ca30 (report)
- CISA — Aa20 302A Ransomware%20 Activity Targeting The Healthcare And Public Health Sector (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Anchor (report)
- Palo Alto Unit 42 — Ryuk Ransomware (report)
- isc.sans.edu — 27308 (report)
- cybersecurity.att.com — Trickbot Bazarloader In Depth (report)
- technical.nttsecurity.com — Trickbot Variant Anchor Dns Communicating Over Dns (report)
- cocomelonc.github.io — Malware Pers 4 (report)
- thedfirreport.com — Bazar Drops The Anchor (report)
- medium.com — Anchor And Lazarus Together Again 24744E516607 (report)
- labs.sentinelone.com — Deep Dive Into Trickbot Executor Module Mexec Hidden Anchor Bot Nexus Operations (report)
- hello.global.ntt — Trickbot Variant Communicating Over Dns (report)
- labs.sentinelone.com — The Deadly Planeswalker How The Trickbot Group United High Tech Crimeware Apt (report)
- kryptoslogic.com — Adjusting The Anchor (report)
- MITRE ATT&CK — S0504 (report)