Netskope Threat Labs

ServHelper

ATP Sandbox Adv. HeuristicsNetskope IPS

ServHelper is a backdoor written in Delphi that researchers first observed in late 2018, typically delivered as a DLL file in campaigns attributed to TA505.

First seen
May 2022
Last seen
September 2026
Servhelper

15 techniques across 6 tactics.

TA0002 Execution

TA0003 Persistence

TA0005 Stealth

TA0007 Discovery

  • T1033System Owner/User Discovery
  • T1082System Information Discovery

TA0008 Lateral Movement

TA0011 Command and Control

Alert Name
Script-PowerShell.Trojan.Servhelper
Win32.Backdoor.Servhelper
Win32.Backdoor.ServHelper