ANELLDR
MITRE ATT&CK: S9027 View on attack.mitre.org
Aliases: ANELLDR
- First seen
- 2018-01-01 00:00:00
- Malware type
- loader
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:09:09
Targeted industries: government-and-public-sector defense-and-aerospace
Context
ANELLDR, a loader that has been in use since at least 2018, was designed to decrypt and execute UPPERCUT in memory. ANELLDR can use anti-analysis techniques and is known to share code overlap with HiddenFace.
Detection coverage
- 215 Sigma rules
Malware & tools used
- Native API (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- DLL (attack-pattern)
- Debugger Evasion (attack-pattern)
- Junk Code Insertion (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
Used by threat actors
- Operation AkaiRyū (campaign)
Reports & references
- Trend Micro — Return Of Anel In The Recent Earth Kasha Spearphishing Campaign (report)
- ESET — Operation Akairyu Mirrorface Invites Europe Expo 2025 Revives Anel Backdoor (report)
- MITRE ATT&CK — S9027 (report)