ServHelper Backdoor
ServHelper is a newly observed Delphi-based backdoor believed to have been created by the TA505 advanced persistent threat group. It appears to be in active development, with new variants published every few days.
Summary
ServHelper is a newly observed Delphi-based backdoor believed to have been created by the TA505 advanced persistent threat group. It appears to be in active development, with new variants published every few days.
Affected platforms
The following platforms are known to be affected:
Threat details
It is delivered via malicious macros distributed in DOC, PUB, PDF and WIZ files in phishing campaigns. When opened, these will download and install ServHelper. Some variants will use links to file-hosting platforms in place of macros.
Once installed, will connect to a command and control server before awaiting further commands. Newer variants will also attempt to establish an SSH tunnel through port 3389 and can monitor web browser profiles on affected devices.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:49 pm