logo

Lazarus_Group__2019__sentinel-one-sentine-6.pdf

ID: 3a94f6d0-150a-4293-93ec-6ab2163b1af9

STIX ID: report--3a94f6d0-150a-4293-93ec-6ab2163b1af9

Threat Score

78/100

Uploaded: 2026-08-15

Published Date: 2019-12-12

Last Modified Date: 2019-12-12

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
SentinelLabs presents a technical analysis of the Anchor project, a modular evolution of TrickBot that functions as an all-in-one attack framework for enterprise environments; the report details installer/deinstaller components, bot behaviour, loaders (Meterpreter/Metasploit, CobaltStrike, Terraloader), a POS-focused memory scraper (Memscraper) with HTTP and DNS exfiltration, PowerShell-based delivery chains, PDB artifacts, and numerous IOCs and YARA rules, and notes overlaps with known APT tooling (e.g., PowerRatankba/Lazarus) raising attribution questions.