Anchor

MITRE ATT&CK: S0504 View on attack.mitre.org

Aliases: Anchor_DNS, Anchor

First seen
2018-01-01 00:00:00
Malware type
backdoor, rat
Family
Malware family
Operating systems
linux, windows
Last IoC activity
2026-05-21 19:31:27
Profile updated
2026-07-07 12:41:08

Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical

Context

Anchor is one of a family of backdoor malware that has been used in conjunction with TrickBot on selected high profile targets since at least 2018.

Detection coverage

  • 1 YARA rules
  • 474 Sigma rules

Malware & tools used

  • Non-Application Layer Protocol (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Cron (attack-pattern)
  • Unix Shell (attack-pattern)
  • Web Protocols (attack-pattern)
  • Code Signing (attack-pattern)
  • DNS (attack-pattern)
  • Windows Service (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • Software Packing (attack-pattern)
  • NTFS File Attributes (attack-pattern)
  • Service Execution (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Fallback Channels (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Anchor_Auto (yara-rule)

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • cybereason.com — Dropping Anchor From A Trickbot Infection To The Discovery Of The Anchor Malware (report)
  • CrowdStrike — Report2021Gtr (report)
  • securityintelligence.com — Itg08 Aka Fin6 Partners With Trickbot Gang Uses Anchor Framework (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • bleepingcomputer.com — Karakurt Revealed As Data Extortion Arm Of Conti Cybercrime Syndicate (report)
  • netscout.com — Dropping Anchor (report)
  • medium.com — Anchor Dns Malware Family Goes Cross Platform D807Ba13Ca30 (report)
  • CISA — Aa20 302A Ransomware%20 Activity Targeting The Healthcare And Public Health Sector (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Anchor (report)
  • Palo Alto Unit 42 — Ryuk Ransomware (report)
  • isc.sans.edu — 27308 (report)
  • cybersecurity.att.com — Trickbot Bazarloader In Depth (report)
  • technical.nttsecurity.com — Trickbot Variant Anchor Dns Communicating Over Dns (report)
  • cocomelonc.github.io — Malware Pers 4 (report)
  • thedfirreport.com — Bazar Drops The Anchor (report)
  • medium.com — Anchor And Lazarus Together Again 24744E516607 (report)
  • labs.sentinelone.com — Deep Dive Into Trickbot Executor Module Mexec Hidden Anchor Bot Nexus Operations (report)
  • hello.global.ntt — Trickbot Variant Communicating Over Dns (report)
  • labs.sentinelone.com — The Deadly Planeswalker How The Trickbot Group United High Tech Crimeware Apt (report)
  • kryptoslogic.com — Adjusting The Anchor (report)
  • MITRE ATT&CK — S0504 (report)

External references