AnchorDNS

First seen
2019-09-01 00:00:00
Malware type
backdoor
Profile updated
2026-07-07 12:59:15

Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications

Context

Backdoor deployed by the TrickBot actors. It uses DNS as the command and control channel as well as for exfiltration of data.

Reports & references

  • intezer.com — Top Linux Cloud Threats Of 2020 (report)
  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • mal-eats.net — Campo New Attack Campaign Targeting Japan (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Anchor Dns (report)
  • securityintelligence.com — New Malware Trickbot Anchordns Backdoor Upgrades Anchormail (report)
  • hello.global.ntt — Trickbot Variant Communicating Over Dns (report)
  • netscout.com — Dropping Anchor (report)
  • medium.com — Anchor Dns Malware Family Goes Cross Platform D807Ba13Ca30 (report)
  • mal-eats.net — Campo New Attack Campaign Targeting Japan (report)
  • domaintools.com — Finding Anchordns C2S With Iris Investigate (report)
  • cyware.com — Trickbots Anchordns Is Now Upgraded To Anchormail A21F5490 (report)
  • CISA — Aa20 302A Ransomware%20 Activity Targeting The Healthcare And Public Health Sector (report)

External references