Anchor is a Windows backdoor associated with the TrickBot ecosystem and operated by the TrickBot group, also tracked as Wizard Spider, GOLD BLACKBURN, and ITG23. It emerged as a TrickBot derivative intended for more targeted, enterprise-focused intrusions and long-term post-compromise access rather than broad commodity banking fraud alone. Public reporting also refers to a DNS-enabled variant, commonly called Anchor DNS, that uses DNS-based command and control to improve stealth and resilience.
Anchor supports persistence through scheduled tasks and has been observed using NTFS features to hide files for defense evasion. It can remove deployment artifacts by self-deleting its dropper after successful installation. The malware can profile compromised hosts by determining external IP address and geolocation information, and it can maintain communications through secondary command-and-control servers if primary infrastructure is unavailable. Reporting also notes use of a PowerShell-and-WMI method to delete Volume Shadow Copies, indicating anti-recovery or cleanup functionality in some deployments.
Within the TrickBot intrusion chain, Anchor has been deployed alongside tooling such as BazaLoader, Cobalt Strike, and PowerTrick, and has been linked to follow-on ransomware operations including Ryuk and Conti. It has been described as part of a broader post-exploitation framework used for covert malware delivery, persistence, evidence removal, and targeted data extraction in enterprise environments. Some reporting states that the framework was designed to load or support additional offensive tooling such as Metasploit, Cobalt Strike, TerraLoader, and PowerShell Empire.
Anchor has been used in corporate network intrusions and is closely tied to financially motivated cybercrime operations that evolved toward hands-on-keyboard enterprise compromise and ransomware enablement. Although some commentary has suggested overlap with Lazarus-linked tooling, the high-confidence attribution consistently supported is to the TrickBot cluster and its operators.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Until a new TrickBot derivative project called “Anchor” was discovered.
Trickbot’s developers were also credited with developing the Anchor backdoor.
Anchor is publicly attributed to the Trickbot group... Anchor uses multiple methods to delete VSCs including a call to PowerShell that uses WMI to delete shadow copies.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon execution it installs itself as a cron job, determines the public ip for the host and then begins to beacon via DNS queries to its C2 server.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
What is out of the question, however, is the sophistication of this technology including an integrated methodology of loading such frameworks Metasploit, Cobalt Strike, TerraLoader, and PowerShell Empire to perform further victim post-exploitation.
What is out of the question, however, is the sophistication of this technology including an integrated methodology of loading such frameworks Metasploit, Cobalt Strike, TerraLoader, and PowerShell Empire to perform further victim post-exploitation.
Upon execution it installs itself as a cron job, determines the public ip for the host and then begins to beacon via DNS queries to its C2 server.
Upon execution it installs itself as a cron job, determines the public ip for the host and then begins to beacon via DNS queries to its C2 server.
Anchor consists of several segments each with a specific function: anchorInstaller anchorDeInstaller AnchorBot Bin2hex psExecutor memoryScraper. This structure is designed to secretly upload the malware and clean up all the evidence of the attack.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
U.S. Cyber Command worked to disrupt ITG23’s operations by poisoning configuration files on its command-and-control (C2) servers. Microsoft, the following month, announced its own efforts to disrupt ITG23 by taking down a large number of their C2 servers.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
Anchor DNS malware uses DNS queries to stealthily communicate to C2 servers... The pcap contains several DNS queries with long strings for sub-domain of sluaknhbsoe[.]com .
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
57 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Anchor is presented as a custom flexible fork or variant linked to TrickBot operations, including a DNS-based variant. It is associated with high-value government and corporate targeting and is discussed here as a payload delivered by TrickBot's mexec module.
Named malware distributed by GOLD BLACKBURN.
A stealthy TrickBot-derived attack framework composed of multiple components for installation, cleanup, memory scraping, post-exploitation, persistence, and targeted data extraction in enterprise environments. It is described as an all-in-one framework for compromising higher-profile victims and enabling long-term persistence.
Anchor used DNS tunneling for stealthy C2 communications via long subdomain queries and maintained persistence through a scheduled task running anchorDNS_x64.exe -s.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.