ANELLDR
S9027 · Windows
ANELLDR, a loader that has been in use since at least 2018, was designed to decrypt and execute UPPERCUT in memory. ANELLDR can use anti-analysis techniques and is known to share code overlap with HiddenFace.
ATT&CK S9027
Sigma rules0
YARA rules0
Live IOCs0