AnchorMail
Aliases: ANCHOR.MAIL, Delegatz
- Malware type
- backdoor, trojan
- Family
- Malware family
- Profile updated
- 2026-07-07 14:21:47
Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector
Targeted regions: country_code:us country_code:ca country_code:gb
Context
AnchorMail is a sophisticated backdoor, part of the Anchor family, often associated with TrickBot group operations. It is used to steal data and provide remote access to compromised systems, frequently targeting high-value sectors such as finance and healthcare.
Reports & references
- securityintelligence.com — New Malware Trickbot Anchordns Backdoor Upgrades Anchormail (report)
- cyware.com — Trickbots Anchordns Is Now Upgraded To Anchormail A21F5490 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Anchormail (report)
- securityintelligence.com — Trickbot Group Systematically Attacking Ukraine (report)
- blog.google — Initial Access Broker Repurposing Techniques In Targeted Attacks Against Ukraine (report)