TA505 continued to evolve its ServHelper operations from phishing-led intrusions into broader multi-stage malware campaigns targeting financial institutions, retailers, restaurants, government entities, and other organizations across multiple regions. Researchers reported that the group used malicious Office and Publisher attachments, PDF lures, direct executable links, .ISO files, macro-enabled documents, MSI/NSIS installers, and .NET downloaders to deliver ServHelper alongside other malware families including FlawedGrace and FlawedAmmyy. ServHelper appeared in both downloader and tunnel variants, with the tunnel version enabling reverse SSH tunneling for RDP access and browser-profile theft, while later samples added encrypted command-and-control traffic and in-memory execution commands such as runmem and runmemxor.
Later activity showed TA505 adding a GoLang crypter wrapped around a .NET loader to deploy both ServHelper and cryptocurrency miners. The infection chain used PowerShell to fetch payloads, establish persistence, and tamper with Windows services by creating a fake TermService configuration, dropping UPX-packed files under C:\Windows\branding\, and redirecting the ServiceDll registry value to a malicious DLL. One dropped DLL was identified as the ServHelper tunnel variant, while additional components supported RDPWrap-style access, host reconnaissance, and miner deployment for Bitcoin and Ethereum. Across campaigns, researchers also observed shifting infrastructure including HTTP/HTTPS C2, .pw domains, later support for Namecoin .bit domains, and customized loaders and obfuscation intended to improve evasion and maintain long-term access.

Pull IOCs and campaign context straight into your stack.
16 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos investigated an increase in ServHelper activity detected in mid-June 2021 and linked it with moderate confidence to TA505 or a related group. The campaign used compromised legitimate websites hosting signed MSI installers, as well as Raccoon stealer, Amadey, Go-based droppers, and PowerShell chains to install ServHelper and sometimes cryptominers.
On December 13, 2018, TA505 ran another large ServHelper downloader campaign targeting retail and financial services organizations. In this campaign, ServHelper downloaded and executed FlawedGrace.
On November 15, 2018, TA505 launched a larger email campaign delivering the ServHelper downloader variant. It targeted financial institutions and the retail industry with .doc, .pub, and .wiz attachments containing macros.
On November 9, 2018, TA505 conducted a relatively small email campaign delivering the ServHelper tunnel variant. The campaign primarily targeted financial institutions using malicious Word or Publisher attachments with macros.
TA505 began distributing a newly identified backdoor named ServHelper in November 2018. The malware appeared in tunnel and downloader variants.
During much of 2018, researchers observed TA505 moving from ransomware toward downloaders, backdoors, information stealers, and RATs. This broader shift set the stage for later ServHelper and FlawedGrace campaigns.
Researchers first observed the FlawedGrace remote access trojan in November 2017. Later reporting assessed it was likely written by a different developer than ServHelper.
The Walmart Global Tech report published hashes, URLs, command-and-control domains, named pipes, and YARA rules associated with the TA505 campaign using the GoLang crypter, ServHelper, and miner payloads. This disclosure provided technical detection details for defenders.
In recent activity described by Walmart Global Tech, TA505 used a GoLang crypter wrapped around a .NET loader to deploy both ServHelper and cryptocurrency miners. The chain included PowerShell stages, persistence changes to TermService, and dropped UPX-packed files under C:\Windows\branding\.
In early August, TA505 used a new macro style and a .DLL-based FlawedAmmyy downloader in a campaign targeting Canada. The macros instantiated Internet Explorer to retrieve an XOR-encoded payload, likely to evade some firewall controls.
TA505 targeted government agencies in Saudi Arabia, Oman, and Qatar with finance- or insurance-themed XLS and DOC attachments. It also targeted Turkish educational and government institutions with invoice- or payroll-themed VBA documents delivering FlawedAmmyy or ServHelper.
A campaign targeting Romanian banks used the subject line "Fw: copie COC L5H3" and delivered malware through an .ISO attachment. The chain used a .NET downloader, MSI installer, and NSIS installer to infect victims with ServHelper.
A campaign targeting thousands of Korean businesses used .ISO attachments disguised as confirmed airline tickets. These infections delivered FlawedAmmyy via .LNK files or a .NET downloader, with some emails also using malicious Excel attachments or embedded URLs.
Trend Micro reported TA505 introducing .ISO image attachments, a .NET downloader, a new macro delivery style, and newer ServHelper builds. Updated ServHelper samples added encrypted strings and XOR-encrypted HTTP C2 traffic, along with new runmem and runmemxor commands.
In the campaigns described by Trend Micro, TA505 expanded targeting to countries including Turkey, Serbia, Romania, South Korea, Canada, the Czech Republic, and Hungary, while also hitting Saudi Arabia, Oman, Qatar, India, and the United States. The actor used ServHelper and FlawedAmmyy with varied lures and delivery methods.
A mid-July campaign targeted Turkish and Serbian banks with phishing emails carrying .ISO attachments. The infection chain used .LNK files, remote MSI files, and NSIS installers to deploy ServHelper.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 250 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
blog.talosintelligence.com
Open sourcemedium.com
Open sourcegdatasoftware.com
Open sourceblog.trendmicro.com
Open sourceproofpoint.com
Open sourcebinarydefense.com
Open sourceavira.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.