ServHelper is a Windows backdoor associated with the TA505 cybercriminal threat cluster. First observed in 2018, it has been used in campaigns targeting sectors including finance and retail and has also appeared as a follow-on payload in broader TA505 intrusion chains. ServHelper exists in multiple forms, including an initial-stage variant and a more feature-rich RAT-like variant sometimes referred to as the Tunnel variant. It has also been used alongside additional monetization payloads such as the LoudMiner cryptominer and has been observed in operations that delivered other malware families including Predator Stealer, FlawedAmmyy, and NetSupport.
ServHelper provides operators with backdoor access for command execution and host information retrieval. Documented behaviors include executing PowerShell to gather system information, enumerating the current username, downloading and executing DLL payloads through trusted Windows utilities, and using scheduled tasks to perform malicious actions. Some variants include self-deletion capability for cleanup and anti-forensics. Persistence has been established through Windows autorun mechanisms and, in some campaigns, by modifying Terminal Services components to load the malware through a service DLL chain.
Observed ServHelper delivery has included phishing email attachments and malicious document lures, including Excel 4.0 macro-based infection chains. TA505-linked campaigns have also used layered loaders and obfuscation around ServHelper, including NSIS installers, PowerShell-based staging, and signed or packed components. Certain variants incorporated anti-analysis and anti-virtualization checks, attempted privilege escalation using UAC bypass techniques, and added Windows Defender exclusions to reduce detection. ServHelper has also been associated with abuse of native Windows binaries such as rundll32 and msiexec as part of execution and defense-evasion tradecraft.
The malware is primarily a Windows-focused backdoor used for post-compromise access, staging, and follow-on payload delivery within TA505 operations. Its role in campaigns has ranged from establishing persistent remote access to supporting broader criminal objectives such as credentialed intrusion, malware deployment, and covert cryptocurrency mining.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
New ServHelper Variant Employs Excel 4.0 Macro to Drop Signed Payload.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
TA505 semble avoir procédé à la distribution de ses charges malveillantes uniquement par campagnes de courriels d’hameçonnage... L’unique vecteur d’infection pour l’instant connu du mode opératoire TA505 demeure le courriel d’hameçonnage incluant une pièce jointe ou un lien malveillant.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The script ‘ready.ps1’ sets up a class for a few functions and detonates the ‘get-content.ps1’ script which handles installing and setting up a number of executable files along with a backdoor and persistence.
As it proceeds, it will execute a PowerShell script file named upgrade.ps1 ... The executed PowerShell script will decrypt and invoke the main Installer of ServHelper. | After decrypting, it will use IEX (Invoke Expression) that will enable it to evaluate and execute the command.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
it will add the installed RDP Wrapper Library 'appcache.xml' as TermService’s Service DLL as its main target to be executed... This modification done by ServHelper will make sure it runs every time the service is started.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The PowerShell module changes the registry keys related to the Windows service Terminal Server. The Terminal Server service is changed so that it listens on a non-default TCP port 7201...
A new Remote Desktop service Termservice is created and its ServiceDLL value is set to point into the ServHelper DLL loader C:\Windows\branding\mediasrv.png.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
A new Remote Desktop service Termservice is created and its ServiceDLL value is set to point into the ServHelper DLL loader C:\Windows\branding\mediasrv.png.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The PowerShell command was encrypted with a combination of Base64 encoding and Triple DES Algorithm... Afterwards, it will prepare the payload to be dropped by decrypting it using Base64 decoding and GZip decompression.
there are two files that do not appear to be related to RDPWrap which are also UPX packed.
These files are written as hardcoded files to disk. $fldr=$env:systemroot+"\branding\" $bf="mediasvc.png" $rf="mediasrv.png" $cf="wupsvc.jpg"
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
Upon execution, the loader will check if it is running on a virtualized environment... by checking for the presence of a file, C:\aaa_TouchMeNot_.txt ... If the file is present, installation will stop.
it will add the installed RDP Wrapper Library 'appcache.xml' as TermService’s Service DLL as its main target to be executed... This modification done by ServHelper will make sure it runs every time the service is started.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Over the last six years there has been an increased shift by malware authors to secure their C&C communications using the SSL/TLS protocol to stymie detection and blend in with normal traffic.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
258 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
53 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
A sophisticated backdoor used in a targeted phishing campaign against a financial institution. It uses LOLBins such as msiexec.exe and rundll32.exe for payload delivery and execution, performs reconnaissance to identify high-value administrator systems, communicates with dynamic C2 infrastructure, selectively establishes persistence via the registry, supports downloading additional modules, and includes self-delete capability to remove evidence.
Backdoor that attempts to enumerate the victim username.
Mentioned for code/obfuscation overlap with a PowerShell stage in the analyzed package; not the main malware under discussion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.