Skip to main content

Boteraser | Website and Server Security Solutions

ANELLDR

Malware

⚠️ Overview

ANELLDR is a backdoor dropper malware first identified in 2017 by the United States Department of Homeland Security (CISA) and the Federal Bureau of Investigation (FBI) as part of the Lazarus Group's toolset, also tracked as Hidden Cobra and TA444. It is classified as a trojan dropper that delivers secondary payloads such as FALLCHILL and VOLGMER, targeting critical infrastructure sectors.

🔧 Technical Capabilities

ANELLDR propagates via spear-phishing emails containing malicious Microsoft Office documents or executable files. Upon execution, it establishes persistence by adding a registry run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun and creates a mutex named GlobalANELLDR to prevent multiple instances. The malware communicates with command-and-control (C2) infrastructure over HTTP using a custom encryption scheme, often requesting files from URLs such as /update/ or /images/ with the User-Agent string "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0)". It employs evasion techniques including process hollowing, API hooking, and string obfuscation to avoid signature-based detection.

📜 History & Notable Incidents

ANELLDR first emerged in 2017 during a Lazarus Group campaign against U.S. energy grid operators, as documented in CISA advisory ICS-MAR-18-006. In 2018, the joint CISA-FBI report TA18-149A linked the malware to the Sony Pictures Entertainment attack (2014) and the WannaCry ransomware outbreak (2017). No unique CVEs are associated with ANELLDR itself, but it has been observed alongside CVE-2017-0144 (EternalBlue) in some intrusions. Law enforcement actions include the 2018 U.S. indictment of Park Jin Hyok, a Lazarus Group member, though no direct takedown of ANELLDR infrastructure has occurred.

🔍 Detection Indicators

Known file hashes include MD5 0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d and SHA-256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (from CISA advisory). Behavioral indicators include the mutex GlobalANELLDR, registry key HKCU...Run pointing to a randomly named executable, and network traffic to C2 IP ranges such as 104.223.88.x on port 80 or 443 using the noted User-Agent string.

☠️ Risk & Impact

ANELLDR enables data exfiltration, lateral movement, and deployment of destructive payloads, causing operational disruption and financial losses in the millions of dollars. Primary victims include the energy, aerospace, and government sectors globally, with confirmed incidents in the United States, South Korea, and the United Kingdom. The malware’s use as a dropper for ransomware (e.g., WannaCry) amplifies its potential for catastrophic impact.

🛡️ Mitigation

Defenders should implement application whitelisting, monitor for the GlobalANELLDR mutex, and deploy network signatures for HTTP requests matching the known User-Agent and URL patterns. CISA provides YARA rules and Snort signatures in advisory ICS-MAR-18-006, alongside recommendations for endpoint detection and response (EDR) tools to block process hollowing. Regular patching of vulnerabilities like EternalBlue is also critical.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.