“DEV-0193 develops, distributes, and manages many different payloads, including Trickbot, Bazaloader, and AnchorDNS.”
AnchorDNS
AnchorDNS is a Windows backdoor associated with the TrickBot cybercriminal group, tracked by Microsoft as DEV-0193 or Trickbot LLC.
AnchorDNS
Family profile
AnchorDNS is a Windows backdoor associated with the TrickBot cybercriminal group, tracked by Microsoft as DEV-0193 or Trickbot LLC. This group develops, distributes, and manages AnchorDNS alongside TrickBot and BazaLoader and is associated with the Ryuk, Conti, and Diavol ransomware operations. AnchorDNS uses process doppelgänging to execute malicious code under the guise of legitimate Windows processes. This process-injection technique abuses Transactional NTFS to create a malicious executable image in memory and roll back the corresponding disk changes, supporting stealthy execution and defense evasion.
Capabilities
- Defense Evasion
- Process Injection
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK