ANEL, also known as UPPERCUT, is a Windows backdoor associated with the China-aligned cyber-espionage ecosystem around APT10, including the subgroup tracked as MirrorFace or Earth Kasha. It has been described as an APT10-linked implant that was largely dormant after roughly 2018–2019 before reappearing in later espionage operations. Security reporting has tied its renewed use to campaigns against organizations in Japan and Taiwan, as well as a 2024 operation against a Central European diplomatic institute connected to Expo 2025-themed lures. Victimology linked to operators using ANEL includes government, diplomatic, media, research, political, think tank, academic, defense, high-technology, and manufacturing targets, with activity consistent with long-term intelligence collection rather than financially motivated crime.
ANEL functions as a backdoor that supports remote command-and-control and host reconnaissance. Documented capabilities include collecting the current logged-on username, obtaining local time zone and timestamp information, and capturing desktop screenshots for transmission to operator infrastructure. Its communications have used Base64 encoding, and some versions have additionally used Blowfish encryption with hard-coded keys, with later variants reportedly using keys tailored to specific command-and-control endpoints. Operationally, ANEL has been loaded into memory by a dedicated loader and has also been launched through DLL side-loading chains that abuse legitimate signed executables, reflecting a strong emphasis on defense evasion.
Observed delivery has centered on targeted spearphishing. Campaigns have used malicious Microsoft Office documents, including Word files with VBA-based execution chains and malicious templates, as well as malicious Excel content in some related operations. In Operation AkaiRyū, operators used tailored phishing exchanges and document-themed lures to trigger installation of ANEL, including side-loading via legitimate software components and abuse of a signed McAfee executable. Historical APT10 activity has also included malicious Office attachments that ultimately installed ANEL. These tradecraft patterns place ANEL within mature espionage intrusion chains that combine social engineering, staged loaders, and stealthy post-compromise persistence and access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Alongside the new target, the group revived ANEL (also called UPPERCUT), an APT10 backdoor that had been dormant since roughly 2018-2019, moving away from LODEINFO, its previous mainstay implant.
Alongside the new target, the group revived ANEL (also called UPPERCUT), an APT10 backdoor that had been dormant since roughly 2018-2019, moving away from LODEINFO, its previous mainstay implant.
Alongside the new target, the group revived ANEL (also called UPPERCUT), an APT10 backdoor that had been dormant since roughly 2018-2019, moving away from LODEINFO, its previous mainstay implant.
Third party reporting also suggests that the group has adopted tools including the ANEL backdoor and Cobalt Strike.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
While Trend Micro reported Windows Management Instrumentation (WMI) and explorer.exe as the execution proxy pair for ANEL, we unearthed another pair: WMI and wlrmdr.exe (Windows logon reminder).
The LNK file runs cmd.exe with a set of PowerShell commands to drop additional files...
The LNK file runs cmd.exe with a set of PowerShell commands to drop additional files...
Priority MITRE ATT&CK Mapping ... Defense Evasion T1027.013 Encrypted/Encoded File Encoded malware strings and obfuscation
MirrorFace used a so-called double file extension, .docx.lnk , to deceive its target.
HiddenFace reads external modules from an AES-encrypted file.
MirrorFace used wlrmdr.exe as an execution proxy to run ANEL.
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Multiple malware and threat groups are described as collecting/deriving local system time, date, timestamp, tick count, or time zone (e.g., "used time /t and net time \ip/hostname for system time discovery"; "collects the timestamp from the victim’s machine"; "can collect the time zone information from the system").
Examples include: "ChChes communicates to its C2 server over HTTP and embeds data within the Cookie HTTP header," "UPPERCUT has used HTTP for C2, including sending error codes in Cookie headers," and "GoldMax has used HTTPS and HTTP GET requests with custom HTTP cookies for C2."
ANEL, HiddenFace and the customised AsyncRAT beacon to C2 over web protocols.
C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding... APT19 HTTP malware variant used Base64 to encode communications to the C2 server... APT33 has used base64 to encode command and control traffic.
HiddenFace communicates with its C&C server over an encrypted channel.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT10-linked backdoor revived by MirrorFace; loaded into memory via the ANELLDR side-loading chain and used for command-and-control over web protocols.
Backdoor associated with APT10/Earth Kasha reporting; also referenced in FBI FLASH as UPPERCUT/ANEL.
Malware installed via malicious Word templates and executed through signed binary abuse and WMI proxy execution during Operation AkaiRyū.
Malware used by MirrorFace in long-running cyber-espionage activity targeting Japan (as referenced alongside NOOPDOOR).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.