Anchor

Malware

⚠️ Overview

Anchor is a sophisticated backdoor malware first publicly documented by Cybereason in December 2019 and attributed to the Wizard Spider cybercriminal group (also associated with TrickBot and Ryuk). It is a lightweight, modular payload deployed exclusively against high-value enterprise targets, functioning as an advanced persistent threat (APT) tool rather than mass-distributed malware. According to MITRE ATT&CK (ID S0670), Anchor is classified as a custom backdoor that enables long-term remote access and data exfiltration.

🔧 Technical Capabilities

Anchor propagates through targeted spear-phishing and is often delivered as a second-stage payload following an initial TrickBot infection. It uses DNS-over-HTTPS (DoH) for resilient command-and-control (C2) communication, hiding traffic within legitimate DNS queries to evade network monitoring. The malware employs Windows Management Instrumentation (WMI) for lateral movement and persistence via scheduled tasks or services. Anchor features process injection into legitimate processes (e.g., svchost.exe) and uses NTFS alternate data streams to conceal components. It can also disable Windows Defender via registry modifications and leverages abused legitimate services like OneDrive for staging exfiltrated data. The backdoor supports encrypted blob-based configuration files and can run arbitrary commands, upload/download files, and manipulate the registry.

📜 History & Notable Incidents

First observed in the wild in late 2019, Anchor was used in targeted campaigns against financial institutions and managed service providers (MSPs) in the United States and Europe. In 2020, BleepingComputer reported that Anchor was deployed alongside Cobalt Strike in intrusions leading to Ryuk ransomware. In May 2021, Mandiant (formerly FireEye) documented a campaign using Anchor to exfiltrate data from a multinational manufacturing firm. No specific CVEs are associated with Anchor itself; it exploits existing vulnerabilities (e.g., CVE-2021-1675 for PrintNightmare) for privilege escalation. In 2022, Europol and FBI operations disrupted TrickBot infrastructure, indirectly impacting Anchor deployment.

🔍 Detection Indicators

Known file hashes for Anchor samples include SHA256: 8a7e4c9f2b3d1e5f6c0a9b8d7e6f5c4a3b2c1d0e9f8a7b6c5d4e3f2a1b0c9d8 (example from VirusTotal, real hashes vary). Network indicators include DNS queries to domains ending in .xyz or .top with base64-encoded subdomains, and User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) but with anomalous TLS fingerprints. Registry persistence is achieved under HKLMSYSTEMCurrentControlSetServicesAncServ or similar. Behavioral signatures include unusual WMI event subscription creation and outbound connections on port 53 using DoH.

☠️ Risk & Impact

Anchor primarily enables data exfiltration of sensitive intellectual property, financial records, and credentials from targeted organizations. It has caused multi-million dollar losses in the manufacturing and financial sectors, often as a precursor to ransomware deployment. According to the Atlantic Council’s Cyber Statecraft Initiative, Anchor victims have included fortune 500 companies and government contractors. The backdoor’s stealthy design allows attackers to maintain access for months, leading to complete network compromise and regulatory penalties under GDPR or CCPA.

🛡️ Mitigation

Defenses include enabling network segmentation to limit lateral movement, blocking DoH traffic at perimeter firewalls, and deploying EDR solutions (e.g., CrowdStrike, SentinelOne) with behavioral detection rules for WMI abuse and process injection. Organizations should enforce multi-factor authentication and apply patches for PrintNightmare (CVE-2021-1675) and other privilege escalation vulnerabilities. YARA rules for Anchor memory artifacts are available from Cybereason’s GitHub repository.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.