The threat actor TA505 has started to distribute a new Windows backdoor named ServHelper, according to email security firm Proofpoint. The company claims there are two variants, one directed at remote desktop functions and the second which is primarily a downloader for a remote access trojan known as FlawedGrace.