ATT&CKSoftwareServHelper

ServHelper

S0382

Malware.View on attack.mitre.org

About this malware

ServHelper is a backdoor first observed in late 2018. The backdoor is written in Delphi and is typically delivered as a DLL file.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1021.001
Remote Desktop Protocol

ServHelper has commands for adding a remote desktop user and sending RDP traffic to the attacker through a reverse SSH tunnel.

T1033
System Owner/User Discovery

ServHelper will attempt to enumerate the username of the victim.

T1036.010
Masquerade Account Name

ServHelper has created a new user named `supportaccount`.

T1053.005
Scheduled Task

ServHelper contains modules that will use schtasks to carry out malicious operations.

T1059.001
PowerShell

ServHelper has the ability to execute a PowerShell script to get information from the infected host.

T1059.003
Windows Command Shell

ServHelper can execute shell commands against cmd.

T1070.004
File Deletion

ServHelper has a module to delete itself from the infected machine.

T1071.001
Web Protocols

ServHelper uses HTTP for C2.

T1082
System Information Discovery

ServHelper will attempt to enumerate Windows version and system architecture.

T1098.007
Additional Local or Domain Groups

ServHelper has added a user named "supportaccount" to the Remote Desktop Users and Administrators groups.

T1105
Ingress Tool Transfer

ServHelper may download additional files to execute.

T1136.001
Local Account

ServHelper has created a new user named "supportaccount".

T1218.011
Rundll32

ServHelper contains a module for downloading and executing DLLs that leverages rundll32.exe.

T1547.001
Registry Run Keys / Startup Folder

ServHelper may attempt to establish persistence via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ run key.

T1573.002
Asymmetric Cryptography

ServHelper may set up a reverse SSH tunnel to give the attacker access to services running on the victim, such as RDP.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Proofpoint TA505 Jan 2019 Open source
    Schwarz, D. and Proofpoint Staff. (2019, January 9). ServHelper and FlawedGrace - New malware introduced by TA505. Retrieved May 28, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.