Anchor is a malware cluster and operational subset associated with the TrickBot ecosystem rather than a clearly delineated standalone threat actor. It has been described as a custom, flexible fork of the TrickBot codebase used in more targeted post-compromise operations against high-value government and corporate environments. Public reporting has linked Anchor activity to TrickBot operators through shared tooling, delivery infrastructure, and executor modules, including the TrickBot mexec loader and the DNS-oriented Anchor variant commonly referred to as Anchor DNS. Related components discussed alongside Anchor include MemScraper, described as a point-of-sale component of the broader Anchor framework, and PowerTrick, a PowerShell-based framework used by TrickBot/Anchor operators for pivoting within victim networks. Operationally, Anchor is associated with enterprise-focused intrusion activity following initial compromise. Reported behaviors include delivery of secondary and tertiary payloads, internal pivoting, network traversal, data harvesting, and stealth measures intended to reduce detection. Anchor-linked tooling has been observed using NTFS features, including alternate data streams, to hide files as a defense-evasion mechanism. The broader TrickBot/Anchor tradecraft reflected in the reporting includes credential theft, system and network profiling, propagation within compromised environments, and post-exploitation activity oriented toward maintaining access and deploying additional malware. Anchor has been discussed in connection with compromises affecting corporate retail environments and with high-value government and enterprise targeting more broadly. Some reporting has explored possible overlap between environments affected by TrickBot/Anchor and separate activity attributed to Lazarus, but those attribution hypotheses are contested and not sufficiently established to treat Anchor itself as a North Korean actor. Based on the available facts, Anchor is best characterized as a TrickBot-associated intrusion capability used by cybercriminal operators in targeted enterprise intrusions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware operation or variant linked to TrickBot; the report presents mexec as further evidence of the connection between TrickBot and Anchor operations, including delivery of the DNS variant.
The content is a Malpedia/YARA entry for the malware family win.anchor and includes a large actor-alias index. No specific threat actor is explicitly tied to operational use of Anchor within the provided content.
Presented as a distinct activity cluster/framework associated with TrickBot operations, used for foothold persistence and post-compromise activity in victim environments.
Uses NTFS features to hide files.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.