AnchorDNS
- First seen
- 2019-09-01 00:00:00
- Malware type
- backdoor
- Profile updated
- 2026-07-07 12:59:15
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications
Context
Backdoor deployed by the TrickBot actors. It uses DNS as the command and control channel as well as for exfiltration of data.
Reports & references
- intezer.com — Top Linux Cloud Threats Of 2020 (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- mal-eats.net — Campo New Attack Campaign Targeting Japan (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Anchor Dns (report)
- securityintelligence.com — New Malware Trickbot Anchordns Backdoor Upgrades Anchormail (report)
- hello.global.ntt — Trickbot Variant Communicating Over Dns (report)
- netscout.com — Dropping Anchor (report)
- medium.com — Anchor Dns Malware Family Goes Cross Platform D807Ba13Ca30 (report)
- mal-eats.net — Campo New Attack Campaign Targeting Japan (report)
- domaintools.com — Finding Anchordns C2S With Iris Investigate (report)
- cyware.com — Trickbots Anchordns Is Now Upgraded To Anchormail A21F5490 (report)
- CISA — Aa20 302A Ransomware%20 Activity Targeting The Healthcare And Public Health Sector (report)