ANEL, also known as UPPERCUT, is a Windows backdoor and remote access trojan associated with the China-linked espionage ecosystem around APT10, including menuPass and the subgroup MirrorFace/Earth Kasha. It has been used in targeted cyberespionage operations, particularly against organizations in Japan and later in campaigns affecting Taiwan and a European diplomatic target. ANEL has been described as a long-running APT10-linked implant that was revived after several years of limited public reporting and deployed alongside other tooling such as NOOPDOOR/HiddenFace and customized AsyncRAT variants.
ANEL is used for post-compromise remote access, host profiling, and intelligence collection. Reported capabilities include collecting the current logged-on username, obtaining local time and time zone information, gathering proxy configuration, and capturing desktop screenshots for transmission to command-and-control infrastructure. Some variants encode communications with Base64 and use Blowfish-based encryption, with later versions using distinct hardcoded keys per command-and-control endpoint. Earlier reporting also noted code injection into system processes and in-memory loading of decrypted components.
The malware has been delivered through multiple intrusion chains. Observed vectors include spearphishing with malicious Office documents, exploitation of vulnerabilities such as CVE-2017-8759 and CVE-2017-11882, and abuse of Office features including DDEAUTO, Frameset, and Link Auto Update. Operators have also used certutil to decode staged payloads and DLL side-loading to launch ANEL, including loaders that decrypt and load the backdoor into memory from legitimate signed applications. MirrorFace operations in particular have used ANELLDR and other side-loading chains to execute ANEL while reducing detection opportunities.
ANEL also includes privilege-related functionality, including User Account Control bypass. Public analysis of later versions showed substantial compiler-level obfuscation, including opaque predicates and control-flow flattening, indicating deliberate investment in reverse-engineering resistance. The malware is best understood as a mature espionage backdoor used in selective, targeted intrusions by APT10-linked operators against government, diplomatic, academic, media, technology, and related strategic sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
When we tracked ChessMaster back in November, we noted that it exploited the SOAP WSDL parser vulnerability CVE-2017-8759 (patched in September 2017) within the Microsoft .NET framework to download additional malware. | this new campaign used a new backdoor (Detected by Trend Micro as BKDR_ANEL.ZKEI) that leverages the CVE-2017-8759 vulnerability for its cyberespionage activities.
While ChessMaster still uses the previous exploit, it also added more methods to its arsenal: one exploits another vulnerability, CVE-2017-11882 (patched in November 2017), which was also exploited to deliver illegal versions of the Loki infostealer. | this new campaign used a new backdoor (Detected by Trend Micro as BKDR_ANEL.ZKEI) that leverages the CVE-2017-8759 vulnerability for its cyberespionage activities.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT. ROAMINGHOUSE has also used ScnCfg32.exe to sideload vsodscpl.dll to enable UPPERCUT execution.
this new campaign used a new backdoor (Detected by Trend Micro as BKDR_ANEL.ZKEI) that leverages the CVE-2017-8759 vulnerability for its cyberespionage activities.
Alongside the new target, the group revived ANEL (also called UPPERCUT), an APT10 backdoor that had been dormant since roughly 2018-2019, moving away from LODEINFO, its previous mainstay implant.
Alongside the new target, the group revived ANEL (also called UPPERCUT), an APT10 backdoor that had been dormant since roughly 2018-2019, moving away from LODEINFO, its previous mainstay implant.
Third party reporting also suggests that the group has adopted tools including the ANEL backdoor and Cobalt Strike.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
While Trend Micro reported Windows Management Instrumentation (WMI) and explorer.exe as the execution proxy pair for ANEL, we unearthed another pair: WMI and wlrmdr.exe (Windows logon reminder).
例えば、次のようなファイルの作成、プロセスの実行、DLLのロード、通信をしている場合にマルウェアとして検知することができるルールを記述することができます。
The LNK file runs cmd.exe with a set of PowerShell commands to drop additional files...
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
When we tracked ChessMaster back in November, we noted that it exploited the SOAP WSDL parser vulnerability CVE-2017-8759 ... While ChessMaster still uses the previous exploit, it also added more methods to its arsenal: one exploits another vulnerability, CVE-2017-11882...
The victim opens the booby-trapped document or link that starts the loader chain.
At that time, ChessMaster was using ANEL as a backdoor into the target system then injects code into svchost.exe, which then decrypts and activates the embedded backdoor.
ANEL uses one of the startup directories for persistence.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
ANEL version 5.3.0 or later are obfuscated with opaque predicates control flow flattening
Priority MITRE ATT&CK Mapping ... Defense Evasion T1027.013 Encrypted/Encoded File Encoded malware strings and obfuscation
At that time, ChessMaster was using ANEL as a backdoor into the target system then injects code into svchost.exe, which then decrypts and activates the embedded backdoor.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
Examples include: "ChChes communicates to its C2 server over HTTP and embeds data within the Cookie HTTP header," "UPPERCUT has used HTTP for C2, including sending error codes in Cookie headers," and "GoldMax has used HTTPS and HTTP GET requests with custom HTTP cookies for C2."
rules: - ruletype: "ipv4" target: "ipv4" rule: "45.32.116.146"
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
48 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT10-linked backdoor revived by MirrorFace; loaded into memory via the ANELLDR side-loading chain and used for command-and-control over web protocols.
Backdoor associated with APT10/Earth Kasha reporting; also referenced in FBI FLASH as UPPERCUT/ANEL.
Malware installed via malicious Word templates and executed through signed binary abuse and WMI proxy execution during Operation AkaiRyū.
Malware used by MirrorFace in long-running cyber-espionage activity targeting Japan (as referenced alongside NOOPDOOR).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.