ServHelper is a Windows malware family associated with the financially motivated threat actor TA505 and observed in its operations since November 2018. The family includes a backdoor variant providing remote desktop access through reverse SSH tunneling and variants that primarily download or install additional payloads. It has been distributed through phishing emails containing weaponized Microsoft Office documents, including payment-themed Excel spreadsheets, with Windows Installer used to retrieve and execute malicious installation packages. ServHelper campaigns have targeted financial institutions across multiple countries.
Full-featured variants support command execution, host reconnaissance, data theft, and unauthorized remote access. ServHelper can collect the victim's username, execute PowerShell scripts to obtain system information, and download and execute DLL payloads through Rundll32. It creates local accounts and adds them to the Remote Desktop Users and Administrators groups, modifies Terminal Services configuration, and tunnels RDP traffic to attackers. Persistence mechanisms include scheduled tasks, Windows services, and Registry autostart entries. It also supports self-deletion.
ServHelper installation chains have used encrypted and compressed payloads, executable packing, and User Account Control bypass techniques, including DLL side-loading and abuse of an elevated scheduled task. Some deployments use a modified RDP Wrapper Library to enable expanded remote desktop functionality. Variants observed in 2019 downloaded or embedded encrypted archives containing legitimate NetSupport Manager components configured for attacker-controlled remote access. Reduced-functionality variants primarily act as intermediary droppers for NetSupport RAT rather than retaining the family's full backdoor capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ServHelper has created a new user and added it to the "Remote Desktop Users" and "Administrators" groups.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Adversaries may create a local account to maintain access to victim systems. ... Such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
320 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
60 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
A sophisticated backdoor used in a targeted phishing campaign against a financial institution. It uses LOLBins such as msiexec.exe and rundll32.exe for payload delivery and execution, performs reconnaissance to identify high-value administrator systems, communicates with dynamic C2 infrastructure, selectively establishes persistence via the registry, supports downloading additional modules, and includes self-delete capability to remove evidence.
Backdoor used by TA505 since late 2018. The article mentions a variant that relies on NetSupportManager remote control software rather than custom-developed remote access functionality, but does not analyze that variant in detail.
A Delphi backdoor used by TA505 for data theft, spying, and command execution. In the analyzed infection chain, NSIS and PowerShell droppers bypass UAC and install ServHelper through a modified RDP Wrapper Library. ServHelper retrieves a single-byte XOR-encrypted ZIP containing NetSupport Manager components. Additional samples observed in September 2019 have reduced functionality and primarily install NetSupport RAT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.