Skip to content

AnchorDNS

AnchorDNS is a Windows backdoor associated with the TrickBot cybercriminal group, tracked by Microsoft as DEV-0193 or Trickbot LLC.

AnchorDNS

Family profile

AnchorDNS is a Windows backdoor associated with the TrickBot cybercriminal group, tracked by Microsoft as DEV-0193 or Trickbot LLC. This group develops, distributes, and manages AnchorDNS alongside TrickBot and BazaLoader and is associated with the Ryuk, Conti, and Diavol ransomware operations. AnchorDNS uses process doppelgänging to execute malicious code under the guise of legitimate Windows processes. This process-injection technique abuses Transactional NTFS to create a malicious executable image in memory and roll back the corresponding disk changes, supporting stealthy execution and defense evasion.

Capabilities

  • Defense Evasion
  • Process Injection

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

Reported operators

Threat actors

1 named in public reporting
WIZARD SPIDER

“DEV-0193 develops, distributes, and manages many different payloads, including Trickbot, Bazaloader, and AnchorDNS.”

MITRE ATT&CK

AnchorDNS in ATT&CK

4 distinct techniques