Description
ServHelper is a backdoor written in Delphi that researchers first observed in late 2018, typically delivered as a DLL file in campaigns attributed to TA505.
Stats
- First seen
- May 2022
- Last seen
- September 2026
Also known as
Servhelper
MITRE ATT&CK techniques
15 techniques across 6 tactics.
TA0002 Execution
TA0003 Persistence
TA0005 Stealth
Associated groups
Alert name variants
| Alert Name |
|---|
| Script-PowerShell.Trojan.Servhelper |
| Win32.Backdoor.Servhelper |
| Win32.Backdoor.ServHelper |