Anchor

Malware Profile Updated 3 months ago
Download STIX
Preview STIX
Anchor is a type of malware, short for malicious software, that infiltrates systems to exploit and cause damage. It can access systems through various methods such as suspicious downloads, emails, or websites, often unbeknownst to the user. Once inside, it can disrupt operations, steal personal information, or even ransom data. Anchor malware has been associated with Bazar loader and Bazar backdoor, which are linked to Trickbot. Unlike Trickbot and Anchor, the Bazar loader and backdoor decouple campaign and bot information in bot callbacks. The connections between these malwares were discovered during previous research conducted in December 2019. The term "anchor" also appears in different contexts unrelated to malware. For instance, anchor texts of hyperlinks have been used for simulating queries, thus constructing numerous query-document pairs for pre-training. In news broadcasting, the term refers to the main presenter of a news program such as Rob Burgundy, the lead anchor at WMMX, Santa Barbara’s premier news channel. Furthermore, anchors are used in maritime situations to prevent ships from drifting; an incident was reported where a ship's anchor ruptured three underwater lines after the crew abandoned the vessel. In recent events involving the term "anchor", Wayne County Community College District announced a digital equity pilot program to promote digital literacy and inclusion efforts for students and anchor communities served by the college. In the political sphere, Russian President Putin invited former Fox News anchor Tucker Carlson to conduct an interview aimed at influencing the debate in the US on ceasing assistance to Ukraine in the ongoing war. Lastly, in a fictional setting, the story opens with anchor Mitch Kessler facing sexual misconduct allegations.
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
Trickbot-Anchor
1
None
Bazarloader
1
BazarLoader is a form of malware that has been utilized extensively by ITG23, a cybercriminal group. This harmful software infiltrates systems via suspicious downloads, emails, or websites, potentially stealing personal information, disrupting operations, or holding data for ransom. ITG23 has used B
Shellstarter
1
None
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Phishing
Exploit
DNS
Cybercrime
Ransomware
Hardware
Loader
Ios
Cobalt Strike
Bot
Facebook
Scam
Spyware
Australia
Crypter
Outlook
Financial
Reconnaissance
exploitation
Encrypt
Html
Passkey
Ukraine
Cisco
Crowdstrike
Backdoor
Trojan
Payload
RaaS
Downloader
China
Associated Malware
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
ContiUnspecified
3
Conti is a type of malware, specifically ransomware, known for its ability to disrupt operations, steal personal information, and hold data hostage for ransom. The malicious software infiltrates systems via suspicious downloads, emails, or websites, often unbeknownst to the user. It has been used in
BazarUnspecified
2
"Bazar" is a form of malware, a malicious software designed to exploit and damage computer systems. This harmful program can infiltrate systems via suspicious downloads, emails, or websites, often unbeknownst to the user. Once it gains access, it can steal personal information, disrupt operations, o
TrickBotUnspecified
2
TrickBot is a notorious form of malware that infiltrates systems to exploit and damage them, often through suspicious downloads, emails, or websites. Once it has breached a system, TrickBot can steal personal information, disrupt operations, and even hold data hostage for ransom. It has been linked
BumblebeeUnspecified
2
Bumblebee is a type of malware that has been linked to ITG23, a cybercriminal group known for its use of crypters such as Emotet, IcedID, Qakbot, Bumblebee, and Gozi. Distributed via phishing campaigns or compromised websites, Bumblebee enables the delivery and execution of further payloads. The sam
More_eggsUnspecified
1
More_eggs, also known as Golden Chickens, is a malware suite utilized by financially motivated cybercrime actors such as Cobalt Group and FIN6. This malware-as-a-service (MaaS) offering has been identified as the "cyber weapon of choice" by Russia-based cyber gangs. It was first seen in email campai
Trickbot’sUnspecified
1
None
MazeUnspecified
1
Maze is a type of malware, specifically ransomware, that gained notoriety in 2019 for its double extortion tactic. This malicious software infects systems through suspicious downloads, emails, or websites and can steal personal information, disrupt operations, or hold data hostage for ransom. Maze w
DiavolUnspecified
1
Diavol is a type of malware, specifically ransomware, that infiltrates systems to exploit and cause damage. It can infect systems through various channels such as suspicious downloads, emails, or websites, often unbeknownst to the user. Once inside, Diavol can steal personal information, disrupt ope
BazarbackdoorUnspecified
1
BazarBackdoor is a type of malware developed by ITG23, first identified in April 2020. It is commonly distributed via contact forms on corporate websites, bypassing regular phishing emails, which makes it harder to detect. The malware is often associated with BazarLoader, both of which were used ext
Bazar LoaderUnspecified
1
Bazar Loader is a type of malware that infiltrates systems through phishing emails containing links to Google Drive, where the payload is stored. It's associated with the threat actors behind Trickbot and Anchor malware, as evidenced by our previous research from December 2019. The Bazar loader and
Bazar BackdoorUnspecified
1
The Bazar Backdoor is a malicious software (malware) that infiltrates systems through suspicious downloads, emails, or websites. Named after its use of EmerDNS blockchain domains, the Bazar loader and Bazar backdoor are associated with the threat actors behind Trickbot, Anchor malware, and other cyb
Associated Threat Actors
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
Conti Ransomware GangUnspecified
1
The Conti ransomware gang, a notorious threat actor in the cybersecurity landscape, has been responsible for extorting at least $180 million globally. The gang is infamous for the HSE cyberattack in 2021 and has been sanctioned by the National Crime Agency (NCA). In late 2021, experts suggested that
ITG08Unspecified
1
ITG08 is a notable threat actor in the cybersecurity landscape, known for its malicious activities and strategic partnerships with other threat actors. This group has been linked to a series of attacks through Tactics, Techniques, and Procedures (TTPs) consistent with their known modus operandi. Whi
FIN6Unspecified
1
FIN6, also known as ITG08, Skelaton Spider, and MageCart, is a notorious threat actor that has been implicated in various cybercrime activities. The group gained notoriety for stealing credit cards through point-of-sale (POS) systems in retail and hospitality establishments, most notably in the Home
ITG23Unspecified
1
ITG23, also known as the Trickbot/Conti syndicate, is a significant threat actor that has been active since 2016 in the East European cybercrime arena. This group is renowned for its use of Reflective DLL Injection code in many of its crypters, with the presence of these crypters on a file sample be
Associated Vulnerabilities
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
No associations to display
Source Document References
Information about the Anchor Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
SourceCreatedAtTitle
CERT-EU
4 months ago
DIGITAL EQUITY PILOT PROGRAM LAUNCHES AT WAYNE COUNTY COMMUNITY COLLEGE DISTRICT TO PROVIDE TECH SKILLS, ACCESS TO STUDENTS
CERT-EU
5 months ago
State social media law will put burden on companies, cybersecurity expert says | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware | National Cyber Security Consulting
CERT-EU
5 months ago
Search | arXiv e-print repository
CERT-EU
5 months ago
AI and Cybersecurity: A Rob Burgundy Investigation | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware | National Cyber Security Consulting
CERT-EU
5 months ago
Apple TV+ shows and movies: What to watch on Apple TV Plus
CERT-EU
5 months ago
AI and Cybersecurity: A Rob Burgundy Investigation
CERT-EU
5 months ago
Red Sea cable cut by anchor from Houthi ship attack, says internet firm
CERT-EU
5 months ago
Why Putin Warns Of Nuclear War? – OpEd
CERT-EU
5 months ago
Apple TV+ shows and movies: What to watch on Apple TV Plus
CERT-EU
5 months ago
App Instrumentation – The Boat Anchor Around Your Ankle
CERT-EU
5 months ago
Former journalist indicted for allegedly hacking and leaking embarrassing Fox News Tucker Carlson footage | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker | National Cyber Security Consulting
CERT-EU
5 months ago
Apple TV+ shows and movies: What to watch on Apple TV Plus
CERT-EU
5 months ago
Phishing pages hosted on archive.org, (Wed, Feb 21st) – Cybersafe NV
SANS ISC
5 months ago
Phishing pages hosted on archive.org - SANS Internet Storm Center
DARKReading
6 months ago
More Ivanti VPN Zero-Days Fuel Attack Frenzy as Patches Finally Roll
CERT-EU
6 months ago
UC Irvine students sent to hospital after hackers send graphic images to their Discord server | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker | National Cyber Security Consulting
CERT-EU
6 months ago
Rare 'innovation hub' in Bellevue would boost Nebraska as leader in cybersecurity | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware | National Cyber Security Consulting
CERT-EU
7 months ago
Apple TV+ shows and movies: What to watch on Apple TV Plus
CERT-EU
7 months ago
2023: Top 10 Cybersecurity Stats That Make You Go Hmmmmm
CERT-EU
7 months ago
Fake videos spread on Facebook, TikTok and Youtube | #youtubescams | #lovescams | #datingscams | #datingscams | #love | #relationships | #scams | #pof | #match.com | #dating | National Cyber Security Consulting