AnchorDNS is a backdoor malware family associated with the Trickbot Group, tracked by Microsoft as part of DEV-0193 (also referred to as Trickbot LLC). Microsoft identifies DEV-0193 as responsible for developing, distributing, and managing Trickbot, BazaLoader, and AnchorDNS, and notes the group’s broader involvement in Ryuk, Conti, and Diavol ransomware operations. The content explicitly describes AnchorDNS as the “Trickbot Group's AnchorDNS Backdoor.”
High-confidence behavior described in the content includes process doppelgänging injection, a fileless execution technique that abuses Transactional NTFS (TxF) to create and execute a tainted memory section while rolling back on-disk changes. The content states that TrickBot’s AnchorDNS backdoor performs process doppelgänging against legitimate Windows processes including winhlp32.exe, write.exe, explorer.exe, svchost.exe, cmd.exe, notepad.exe, calc.exe, and rundll32.exe. This indicates defense evasion and execution via masquerading within trusted processes.
The provided material does not directly specify AnchorDNS initial infection vectors, victim industries, or concrete indicators of compromise beyond the targeted process names above. It does, however, place AnchorDNS within the Trickbot/DEV-0193 malware ecosystem and notes it appeared in January 2021 (v5.85) in the referenced malware catalog.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DEV-0193 is responsible for developing, distributing, and managing many different payloads, including Trickbot, Bazaloader, and AnchorDNS.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
“The malware uses scheduled tasks that run every 15 minutes to ensure persistence on the victim machine.” / “Ryuk actors have been known to use scheduled tasks and service creation.”
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor/payload family associated with DEV-0193 used to maintain access and support broader criminal operations tied to ransomware activity.
Payload managed by DEV-0193 as part of its malware ecosystem supporting broader cybercriminal and ransomware-associated operations.
Backdoor attributed to the TrickBot group; highlighted for using process doppelgänging injection into legitimate processes to execute code in a fileless/stealthier manner.
AnchorDNS [[URL_b3187638_190]] 2021 年 1 月 (V 5.85)
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.