AnchorMTea
Malware⚠️ Overview
AnchorMTea is a variant of the Anchor backdoor first documented by Palo Alto Networks Unit 42 in May 2020, attributed to the Wizard Spider threat group (also responsible for TrickBot and Conti). It belongs to the category of remote access trojans (RAT) and is used for targeted initial access and lateral movement in ransomware campaigns, particularly those deploying Conti and Ryuk.
🔧 Technical Capabilities
AnchorMTea communicates with its C2 server using a combination of DNS over HTTPS (DoH) and HTTP-based tunneling, employing the proprietary MTea cipher (a variant of the Tiny Encryption Algorithm) for payload encryption. It achieves persistence via scheduled tasks or Windows service creation (MITRE ATT&CK T1053.005, T1543.003) and evades detection by delaying execution, checking for sandbox environments (T1497), and using process hollowing (T1055.012). Propagation occurs through Server Message Block (SMB) brute‑force and exploitation of CVE‑2019‑19781 (Citrix ADC) in the wild. The backdoor supports file exfiltration, keylogging, and remote shell commands via a modular plugin system.
📜 History & Notable Incidents
First observed in early 2020, AnchorMTea was used in high‑profile attacks against healthcare organizations during the COVID‑19 pandemic. In 2021, it was deployed as a precursor to Conti ransomware in attacks targeting U.S. hospital networks. No law enforcement actions have been publicly attributed specifically to AnchorMTea, but the broader Wizard Spider infrastructure was disrupted by the 2022 Conti leaks and subsequent takedowns.
🔍 Detection Indicators
Known SHA‑256 hashes include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample captured August 2020). Behavioral indicators: outbound DNS queries to suspicious domains with Base64‑encoded subdomains (e.g., example[.]anchorc2[.]com), and creation of mutex AnchorMTea_Mutex. Registry persistence at HKCUSoftwareMicrosoftWindowsCurrentVersionRunAnchorSvc.
☠️ Risk & Impact
AnchorMTea enables full remote control of compromised hosts, often leading to data exfiltration, ransomware deployment, and financial losses exceeding millions of dollars per incident. Affected sectors include healthcare, government, and manufacturing, with the U.S. and Europe being primary targets.
🛡️ Mitigation
Organizations should apply patches for CVE‑2019‑19781 and other exploited CVEs, deploy endpoint detection and response (EDR) with behavioral rules for process hollowing and SMB brute‑force, and block outbound DNS over HTTPS to unknown resolvers. Sigma rules for AnchorMTea network indicators are available from the MITRE ATT&CK framework (Technique T1573.002).
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.