ANELLDR

MITRE ATT&CK: S9027 View on attack.mitre.org

Aliases: ANELLDR

First seen
2018-01-01 00:00:00
Malware type
loader
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:09:09

Targeted industries: government-and-public-sector defense-and-aerospace

Context

ANELLDR, a loader that has been in use since at least 2018, was designed to decrypt and execute UPPERCUT in memory. ANELLDR can use anti-analysis techniques and is known to share code overlap with HiddenFace.

Detection coverage

  • 215 Sigma rules

Malware & tools used

  • Native API (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • DLL (attack-pattern)
  • Debugger Evasion (attack-pattern)
  • Junk Code Insertion (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)

Used by threat actors

  • Operation AkaiRyū (campaign)

Reports & references

  • Trend Micro — Return Of Anel In The Recent Earth Kasha Spearphishing Campaign (report)
  • ESET — Operation Akairyu Mirrorface Invites Europe Expo 2025 Revives Anel Backdoor (report)
  • MITRE ATT&CK — S9027 (report)

External references