Anchor

S0504

Malware.View on attack.mitre.org

About this malware

Anchor is one of a family of backdoor malware that has been used in conjunction with TrickBot on selected high profile targets since at least 2018.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1008
Fallback Channels

Anchor can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers.

T1016
System Network Configuration Discovery

Anchor can determine the public IP and location of a compromised host.

T1021.002
SMB/Windows Admin Shares

Anchor can support windows execution via SMB shares.

T1027
Obfuscated Files or Information

Anchor has obfuscated code with stack strings and string encryption.

T1027.002
Software Packing

Anchor has come with a packed payload.

T1053.003
Cron

Anchor can install itself as a cron job.

T1053.005
Scheduled Task

Anchor can create a scheduled task for persistence.

T1059.003
Windows Command Shell

Anchor has used cmd.exe to run its self deletion routine.

T1059.004
Unix Shell

Anchor can execute payloads via shell scripting.

T1070.004
File Deletion

Anchor can self delete its dropper after the malware is successfully deployed.

T1071.001
Web Protocols

Anchor has used HTTP and HTTPS in C2 communications.

T1071.004
DNS

Variants of Anchor can use DNS tunneling to communicate with C2.

T1082
System Information Discovery

Anchor can determine the hostname and linux version on a compromised host.

T1095
Non-Application Layer Protocol

Anchor has used ICMP in C2 communications.

T1105
Ingress Tool Transfer

Anchor can download additional payloads.

View all 20 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. Cyberreason Anchor December 2019 Open source
    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.
  2. Medium Anchor DNS July 2020 Open source
    Grange, W. (2020, July 13). Anchor_dns malware goes cross platform. Retrieved September 10, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.