logo

An Updated ServHelper Tunnel Variant

ID: 6ea3d15c-3e9d-540d-b1dc-42b46ee8716a

STIX ID: report--6ea3d15c-3e9d-540d-b1dc-42b46ee8716a

Feed Name: Binary Defense Blog

Threat Score
78/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

Binary Defense researchers analyzed a new ServHelper variant deployed by TA505: a multi-stage NSIS-packed PowerShell installer that deploys 32/64-bit ServHelper binaries, modified RDPWrap, and uacme-based UAC bypass DLLs to escalate privileges, change RDP configuration, and establish persistence. The backdoor tunnels RDP over an OpenSSH reverse tunnel to attacker-controlled servers, implements anti-sandbox checks, supports browser credential theft and keylogging, communicates with C2 over (base64+XOR)-encoded HTTP(S) using Let’s Encrypt certs, and includes numerous commands and IoCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.