Malware.View on attack.mitre.org
ANELLDR, a loader that has been in use since at least 2018, was designed to decrypt and execute UPPERCUT in memory. ANELLDR can use anti-analysis techniques and is known to share code overlap with HiddenFace.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
ANELLDR code implements anti-analysis techniques including control flow flattening and Mixed Boolean Arithmetic (MBA). |
| T1027.013 Encrypted/Encoded File |
ANELLDR can update its encryption key to AES-256-CBC and re-encrypt its payload, overwriting the original payload file with the newly encrypted data. |
| T1027.016 Junk Code Insertion |
ANELLDR can use junk code for payload obfuscation. |
| T1083 File and Directory Discovery |
ANELLDR can enumerate files in the current directory to search for encrypted payload files. |
| T1106 Native API |
ANELLDR can use the `ZwSetInformationThread` to enable debugger evasion. |
| T1140 Deobfuscate/Decode Files or Information |
ANELLDR can decrypt encrypted payload data using AES-256-CBC and subsequently execute the payload in memory. |
| T1574.001 DLL |
ANELLDR can use DLL sideloading from a legitimate application to initiate execution. |
| T1622 Debugger Evasion |
ANELLDR can call `ZwSetInformationThread` with the second argument set to `ThreadHideFromDebugger (0x11)` to evade being debugged. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.