ANELLDR

S9027

Malware.View on attack.mitre.org

About this malware

ANELLDR, a loader that has been in use since at least 2018, was designed to decrypt and execute UPPERCUT in memory. ANELLDR can use anti-analysis techniques and is known to share code overlap with HiddenFace.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1027
Obfuscated Files or Information

ANELLDR code implements anti-analysis techniques including control flow flattening and Mixed Boolean Arithmetic (MBA).

T1027.013
Encrypted/Encoded File

ANELLDR can update its encryption key to AES-256-CBC and re-encrypt its payload, overwriting the original payload file with the newly encrypted data.

T1027.016
Junk Code Insertion

ANELLDR can use junk code for payload obfuscation.

T1083
File and Directory Discovery

ANELLDR can enumerate files in the current directory to search for encrypted payload files.

T1106
Native API

ANELLDR can use the `ZwSetInformationThread` to enable debugger evasion.

T1140
Deobfuscate/Decode Files or Information

ANELLDR can decrypt encrypted payload data using AES-256-CBC and subsequently execute the payload in memory.

T1574.001
DLL

ANELLDR can use DLL sideloading from a legitimate application to initiate execution.

T1622
Debugger Evasion

ANELLDR can call `ZwSetInformationThread` with the second argument set to `ThreadHideFromDebugger (0x11)` to evade being debugged.

Groups that use it0

None recorded.

Campaigns1

References2

  1. ESET MirrorFace 2025 Open source
    Dominik Breitenbacher. (2025, March 18). Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor. Retrieved May 22, 2025.
  2. Trend Micro Earth Kasha Anel NOV 2024 Open source
    Hiroaki, H. (2024, November 26). Guess Who’s Back - The Return of ANEL in the Recent Earth Kasha Spear-phishing Campaign in 2024. Retrieved April 17, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.