AnchorMail

Aliases: ANCHOR.MAIL, Delegatz

Malware type
backdoor, trojan
Family
Malware family
Profile updated
2026-07-07 14:21:47

Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector

Targeted regions: country_code:us country_code:ca country_code:gb

Context

AnchorMail is a sophisticated backdoor, part of the Anchor family, often associated with TrickBot group operations. It is used to steal data and provide remote access to compromised systems, frequently targeting high-value sectors such as finance and healthcare.

Reports & references

  • securityintelligence.com — New Malware Trickbot Anchordns Backdoor Upgrades Anchormail (report)
  • cyware.com — Trickbots Anchordns Is Now Upgraded To Anchormail A21F5490 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Anchormail (report)
  • securityintelligence.com — Trickbot Group Systematically Attacking Ukraine (report)
  • blog.google — Initial Access Broker Repurposing Techniques In Targeted Attacks Against Ukraine (report)

External references